Vulnerabilities > Custom Popup Builder Project

DATE CVE VULNERABILITY TITLE RISK
2022-06-15 CVE-2022-28612 Unspecified vulnerability in Custom Popup Builder Project Custom Popup Builder
Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.
network
low complexity
custom-popup-builder-project
5.4
2022-02-14 CVE-2022-0214 Improper Validation of Specified Quantity in Input vulnerability in Custom Popup Builder Project Custom Popup Builder
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog
network
low complexity
custom-popup-builder-project CWE-1284
7.5