← WordPress Vulnerabilities
WordPress security by component

Popup Builder

Popup Builder is a WordPress component with 22 published CVE records in this archive. The latest tracked vulnerability was published Jun 04, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: popup-builder

CVE-2019-25744: Popup Builder: Cross-site scripting

Popup Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.49.

PublishedJun 04, 2026
Safe version guidanceSee mitigation notes
Safe version
Jun 04, 2026 CVE-2019-25744
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exploitation requires an authenticated WordPress account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is 3.49.
See mitigation notes
CVE5.1
NVDPending
Feb 19, 2026 CVE-2025-13079
Popup Builder – Create highly converting, mobile friendly marketing popups: A security weakness
Popup Builder – Create highly converting, mobile friendly marketing popups is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Dec 13, 2025 CVE-2025-9856
Popup Builder – Create highly converting, mobile friendly marketing popups: Cross-site scripting
Popup Builder – Create highly converting, mobile friendly marketing popups is affected by cross-site scripting. Exploitation requires at least contributor-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.4
NVDPending
Dec 12, 2024 CVE-2024-9428
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVDPending
Aug 29, 2024 CVE-2024-2541
Popup Builder: Sensitive information exposure
Popup Builder is affected by sensitive information exposure. The vulnerable path is reachable without authentication. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE5.3
NVD7.5
Jun 17, 2024 CVE-2024-3236
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE5.4
NVDPending
Jun 15, 2024 CVE-2024-2544
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exploitation requires at least subscriber-level access. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.4
NVD6.4
Jun 15, 2024 CVE-2023-6696
Popup Builder – Create highly converting, mobile friendly marketing popups: Server-side request forgery
Popup Builder – Create highly converting, mobile friendly marketing popups is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE8.1
NVD8.1
Mar 27, 2024 CVE-2024-30184
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.5
NVDPending
Feb 12, 2024 CVE-2023-6294
Popup Builder: Server-side request forgery
Popup Builder is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.5
NVD7.2
Jan 01, 2024 CVE-2023-6000
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Sep 25, 2023 CVE-2023-3226
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Jul 22, 2022 CVE-2022-29495
Popup Builder: Cross-site request forgery
Popup Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Jul 21, 2022 CVE-2022-32289
Popup Builder: Cross-site request forgery
Popup Builder is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVD4.3
Jul 11, 2022 CVE-2022-1894
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE4.8
NVD4.8
Mar 28, 2022 CVE-2022-0479
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Feb 21, 2022 CVE-2022-0228
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE7.2
NVD7.2
Feb 21, 2022 CVE-2021-25082
Popup Builder: Filesystem traversal
Popup Builder is affected by filesystem traversal. Exposure depends on how the affected operation is made reachable by the site. A crafted path can escape the intended directory and reach files or directories elsewhere on the server.
See mitigation notes
CVE8.8
NVD8.8
Mar 13, 2020 CVE-2020-10196
Popup Builder: Cross-site scripting
Popup Builder is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE6.1
NVD6.1
Mar 13, 2020 CVE-2020-10195
Popup Builder: Privilege escalation or authentication bypass
Popup Builder is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE6.3
NVD6.3
Feb 17, 2020 CVE-2020-9006
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8
Aug 06, 2019 CVE-2019-14695
Popup Builder: SQL injection
Popup Builder is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE9.8
NVD9.8