Vulnerabilities > Code Atlantic > Popup Maker > 1.7.12

DATE CVE VULNERABILITY TITLE RISK
2022-11-21 CVE-2022-3690 Unspecified vulnerability in Code-Atlantic Popup Maker
The Popup Maker WordPress plugin before 1.16.11 does not sanitise and escape some of its Popup options, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks, which could be used against admins
network
low complexity
code-atlantic
4.8
2022-05-09 CVE-2022-1104 Unspecified vulnerability in Code-Atlantic Popup Maker
The Popup Maker WordPress plugin before 1.16.5 does not sanitise and escape some of its Popup settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
network
low complexity
code-atlantic
4.8
2019-10-14 CVE-2019-17574 Authorization Bypass Through User-Controlled Key vulnerability in Code-Atlantic Popup Maker
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress.
network
low complexity
code-atlantic CWE-639
critical
9.1