Vulnerabilities > Essentialplugin > Popup Anything

DATE CVE VULNERABILITY TITLE RISK
2023-03-29 CVE-2022-38077 Cross-Site Request Forgery (CSRF) vulnerability in Essentialplugin Popup Anything
Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.
network
low complexity
essentialplugin CWE-352
8.8
2022-07-25 CVE-2022-2115 Unspecified vulnerability in Essentialplugin Popup Anything
The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting
network
low complexity
essentialplugin
6.1
2021-11-29 CVE-2021-24883 Unspecified vulnerability in Essentialplugin Popup Anything
The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks
network
low complexity
essentialplugin
5.4