Vulnerabilities > Themehunk > WP Popup Builder

DATE CVE VULNERABILITY TITLE RISK
2024-10-16 CVE-2024-9061 Code Injection vulnerability in Themehunk WP Popup Builder
The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5.
network
low complexity
themehunk CWE-94
critical
9.8
2022-09-26 CVE-2022-2404 Unspecified vulnerability in Themehunk WP Popup Builder
The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
network
low complexity
themehunk
6.1
2022-09-26 CVE-2022-2405 Missing Authorization vulnerability in Themehunk WP Popup Builder
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
network
low complexity
themehunk CWE-862
4.3