CM Pop-Up banners <= 1.8.4 - Missing Authorization
medium
The CM Pop-Up – Create engaging popups to capture attention and boost interaction plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.4. This makes it possible for authenticated attackers, with Subscriber-level access and ab...
- CVSS:
- 4.3
- Affected:
- up to 1.8.4
- Fixed in:
- 1.8.5
- Disclosed:
- Jul 16, 2025
CVE-2025-54018 on NVD →
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.8.5
unknown
[en] Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CM Pop-Up banners: from n/a through 1.8.4.
- Affected:
- up to 1.8.5
- Fixed in:
- 1.8.5
- Disclosed:
- Jul 16, 2025
CVE-2025-54018 on NVD →
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.7.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolutions CM Map Locations allows Reflected XSS. This issue affects CM Map Locations: from n/a through 2.0.8.
- Affected:
- up to 1.7.4
- Fixed in:
- 1.7.4
- Disclosed:
- Mar 3, 2025
CVE-2025-24758 on NVD →
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.7.6
unknown
[en] Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can...
- Affected:
- up to 1.7.6
- Fixed in:
- 1.7.6
- Disclosed:
- Nov 26, 2024
CVE-2024-11202 on NVD →
Multiple Plugins <= (Various Versions) - Reflected Cross-Site Scripting via cminds_free_guide Shortcode
medium
Multiple plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the cminds_free_guide shortcode in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can succe...
- CVSS:
- 6.1
- Affected:
- up to 1.7.5
- Fixed in:
- 1.7.6
- Disclosed:
- Nov 25, 2024
CVE-2024-11202 on NVD →
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.7.3
unknown
[en] The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.
- Affected:
- up to 1.7.3
- Fixed in:
- 1.7.3
- Disclosed:
- Sep 12, 2024
CVE-2024-5799 on NVD →
CM Pop-Up Banners <= 1.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The CM Pop-Up Banners for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via campaign data in all versions up to, and including, 1.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- CVSS:
- 6.4
- Affected:
- up to 1.7.2
- Fixed in:
- 1.7.3
- Disclosed:
- Aug 22, 2024
CVE-2024-5799 on NVD →
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.6.6
unknown
[en] The CM Popup Plugin for WordPress WordPress plugin before 1.6.6 does not sanitise and escape some of the campaign settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks
- Affected:
- up to 1.6.6
- Fixed in:
- 1.6.6
- Disclosed:
- Jul 22, 2024
CVE-2024-5004 on NVD →
CM Popup Plugin for WordPress – Popup Maker <= 1.6.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The CM Popup Plugin for WordPress – Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width value in all versions up to, and including, 1.6.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access...
- CVSS:
- 6.4
- Affected:
- up to 1.6.5
- Fixed in:
- 1.6.6
- Disclosed:
- Jul 1, 2024
CVE-2024-5004 on NVD →
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.6.0
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeMindsSolutions CM Popup Plugin for WordPress.This issue affects CM Popup Plugin for WordPress: from n/a through 1.5.10.
- Affected:
- up to 1.6.0
- Fixed in:
- 1.6.0
- Disclosed:
- Dec 20, 2023
CVE-2023-30750 on NVD →
CM Pop-Up banners <= 1.5.10 - Authenticated (Subscriber+) SQL Injection via getStatistics
high
The CM Pop-Up banners plugin for WordPress is vulnerable to generic SQL Injection via the getStatistics function in versions up to, and including, 1.5.10 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated a...
- CVSS:
- 8.8
- Affected:
- up to 1.5.10
- Fixed in:
- 1.6.0
- Disclosed:
- May 3, 2023
CVE-2023-30750 on NVD →
CM Pop-Up banners <= 1.4.10 - Authenticated Stored Cross-Site Scripting
medium
The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...
- CVSS:
- 6.4
- Affected:
- up to 1.4.10
- Fixed in:
- 1.5.0
- Disclosed:
- Mar 27, 2020
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Jeroen Mulder in WordPress CM Pop-Up banners plugin (versions <= 1.4.10).
- Affected:
- up to 1.4.11
- Fixed in:
- 1.4.11
- Disclosed:
- Mar 27, 2020
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.5.0
unknown
The 'CM Pop-Up banners' plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4.10 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...
- Affected:
- up to 1.5.0
- Fixed in:
- 1.5.0
- Disclosed:
- Mar 27, 2020
CM Pop-Up – Create engaging popups to capture attention and boost interaction [cm-pop-up-banners] < 1.4.11
unknown
When saving a new campaign, a user with edit_pages capabilities can store scripts in the campaign’s pop-up content. The code can then be executed on every page on the website.
- Affected:
- up to 1.4.11
- Fixed in:
- 1.4.11
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database