← WordPress Vulnerabilities
WordPress security by component

PopupKit

PopupKit is a WordPress component with 7 published CVE records in this archive. The latest tracked vulnerability was published Feb 10, 2026; the highest CVE/CNA score is 8.5.

Plugin slug: popup-builder-block

CVE-2025-14895: PopupKit: A security weakness

PopupKit is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.

PublishedFeb 10, 2026
Safe version guidanceSee mitigation notes
Safe version
Feb 10, 2026 CVE-2025-14895
PopupKit: A security weakness
PopupKit is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.4
NVDPending
Feb 05, 2026 CVE-2025-13192
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers: SQL injection
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.2
NVDPending
Jan 06, 2026 CVE-2025-14441
Popupkit: A security weakness
Popupkit is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 30, 2025 CVE-2025-69026
PopupKit: A security weakness
PopupKit is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
Dec 18, 2025 CVE-2025-14314
PopupKit: SQL injection
PopupKit is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVDPending
Oct 24, 2025 CVE-2025-10861
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers: Server-side request forgery
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.5
NVDPending
Oct 09, 2025 CVE-2025-10862
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers: SQL injection
Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers is affected by SQL injection. The vulnerable path is reachable without authentication. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.5
NVDPending