plugin

M Wp Popup Vulnerabilities

2 known security issues reported for the M Wp Popup WordPress plugin. Most recent disclosed Jun 14, 2022.

1 high 1 medium

Running M Wp Popup on your site? Check whether your installed version is affected.

Scan your site free

Popup | Custom Popup Builder <= 1.3.1 - Missing Capabilities Check

medium

Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.

CVSS:
6.4
Affected:
up to 1.3.1
Fix:
No patched version reported
Disclosed:
Jun 14, 2022

CVE-2022-28612 on NVD →

Popup | Custom Popup Builder <= 1.3 - Denial of Service

high

The Popup | Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

CVSS:
7.5
Affected:
up to 1.3.1
Fixed in:
1.3.1
Disclosed:
Jan 17, 2022

CVE-2022-0214 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database