plugin

Popup4Phone Vulnerabilities

4 known security issues reported for the Popup4Phone WordPress plugin. Most recent disclosed May 17, 2024.

1 high 1 medium

Running Popup4Phone on your site? Check whether your installed version is affected.

Scan your site free

Popup4Phone [popup4phone] <= 1.3.2 (unfixed + closed)

unknown

[en] The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some of its settings, which could allow high privilege users such as Editor to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 1.3.2
Fix:
No patched version reported
Disclosed:
May 17, 2024

CVE-2024-3580 on NVD →

Popup4Phone [popup4phone] <= 1.3.2 (unfixed + closed)

unknown

[en] The Popup4Phone WordPress plugin through 1.3.2 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against admins.

Affected:
up to 1.3.2
Fix:
No patched version reported
Disclosed:
May 17, 2024

CVE-2024-3231 on NVD →

Popup4Phone <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting

high

The Popup4Phone plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user access...

CVSS:
7.2
Affected:
up to 1.3.2
Fix:
No patched version reported
Disclosed:
Apr 26, 2024

CVE-2024-3231 on NVD →

Popup4Phone <= 1.3.2 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The Popup4Phone plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbitrary we...

CVSS:
4.4
Affected:
up to 1.3.2
Fix:
No patched version reported
Disclosed:
Apr 26, 2024

CVE-2024-3580 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database