WordPress security by component
Popup Builder
Plugin description
Popup Builder is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Jun 04, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
popup-builderLatest vulnerability
CVE-2019-25744: Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.49.
| Safe version |
|
||
|---|---|---|---|
| Jun 04, 2026 |
CVE-2019-25744
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.49.
|
See mitigation notes |
CVE5.1
NVDPending
|
| Feb 19, 2026 |
CVE-2025-13079
Popup Builder – Create highly converting, mobile friendly marketing popups: A security weakness
Popup Builder – Create highly converting, mobile friendly marketing popups is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
|
See mitigation notes |
CVE5.3
NVDPending
|
| Dec 13, 2025 |
CVE-2025-9856
Popup Builder – Create highly converting, mobile friendly marketing popups: Cross-site scripting
Popup Builder – Create highly converting, mobile friendly marketing popups is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.4
NVDPending
|
| Dec 12, 2024 |
CVE-2024-9428
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVDPending
|
| Aug 29, 2024 |
CVE-2024-2541
Popup Builder: Sensitive information exposure
Popup Builder is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
|
See mitigation notes |
CVE5.3
NVD7.5
|
| Jun 17, 2024 |
CVE-2024-3236
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE5.4
NVDPending
|
| Jun 15, 2024 |
CVE-2024-2544
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE7.4
NVD6.4
|
| Jun 15, 2024 |
CVE-2023-6696
Popup Builder – Create highly converting, mobile friendly marketing popups: Server-side request forgery
Popup Builder – Create highly converting, mobile friendly marketing popups is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE8.1
NVD8.1
|
| Mar 27, 2024 |
CVE-2024-30184
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Feb 12, 2024 |
CVE-2023-6294
Popup Builder: Server-side request forgery
Popup Builder is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
|
See mitigation notes |
CVE7.5
NVD7.2
|
| Jan 01, 2024 |
CVE-2023-6000
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Sep 25, 2023 |
CVE-2023-3226
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Jul 22, 2022 |
CVE-2022-29495
Popup Builder: Cross-site request forgery
Popup Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Jul 21, 2022 |
CVE-2022-32289
Popup Builder: Cross-site request forgery
Popup Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE5.4
NVD4.3
|
| Jul 11, 2022 |
CVE-2022-1894
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE4.8
NVD4.8
|
| Mar 28, 2022 |
CVE-2022-0479
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Feb 21, 2022 |
CVE-2022-0228
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE7.2
NVD7.2
|
| Feb 21, 2022 |
CVE-2021-25082
Popup Builder: Filesystem traversal
Popup Builder is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
|
See mitigation notes |
CVE8.8
NVD8.8
|
| Mar 13, 2020 |
CVE-2020-10196
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
|
See mitigation notes |
CVE6.1
NVD6.1
|
| Mar 13, 2020 |
CVE-2020-10195
Popup Builder: Privilege escalation or authentication bypass
Popup Builder is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE6.3
NVD6.3
|
| Feb 17, 2020 |
CVE-2020-9006
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|
| Aug 06, 2019 |
CVE-2019-14695
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
|
See mitigation notes |
CVE9.8
NVD9.8
|