plugin

Popularis Extra Vulnerabilities

6 known security issues reported for the Popularis Extra WordPress plugin. Most recent disclosed Feb 19, 2026.

3 medium

Running Popularis Extra on your site? Check whether your installed version is affected.

Scan your site free

Popularis Extra [popularis-extra] <= 1.2.10 (unfixed)

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Themes4WP Popularis Extra popularis-extra allows Cross Site Request Forgery.This issue affects Popularis Extra: from n/a through <= 1.2.10.

Affected:
up to 1.2.10
Fix:
No patched version reported
Disclosed:
Feb 19, 2026

CVE-2026-25422 on NVD →

Popularis Extra <= 1.2.10 - Cross-Site Request Forgery

medium

The Popularis Extra plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.10. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can...

CVSS:
4.3
Affected:
up to 1.2.10
Fix:
No patched version reported
Disclosed:
Jan 28, 2026

CVE-2026-25422 on NVD →

Popularis Extra [popularis-extra] < 1.2.8

unknown

[en] The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and ab...

Affected:
up to 1.2.8
Fixed in:
1.2.8
Disclosed:
Nov 16, 2024

CVE-2024-10795 on NVD →

Popularis Extra <= 1.2.7 - Authenticated (Contributor+) Post Disclosure

medium

The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access and above,...

CVSS:
4.3
Affected:
up to 1.2.7
Fixed in:
1.2.8
Disclosed:
Nov 15, 2024

CVE-2024-10795 on NVD →

Popularis Extra [popularis-extra] < 1.2.7

unknown

[en] The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pa...

Affected:
up to 1.2.7
Fixed in:
1.2.7
Disclosed:
Oct 4, 2024

CVE-2024-9353 on NVD →

Popularis Extra <= 1.2.6 - Reflected Cross-Site Scripting

medium

The Popularis Extra plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages t...

CVSS:
6.1
Affected:
up to 1.2.6
Fixed in:
1.2.7
Disclosed:
Oct 3, 2024

CVE-2024-9353 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database