Vulnerabilities > Themehunk > WP Popup Builder > 1.2.4

DATE CVE VULNERABILITY TITLE RISK
2022-09-26 CVE-2022-2404 Cross-site Scripting vulnerability in Themehunk WP Popup Builder
The WP Popup Builder WordPress plugin before 1.2.9 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting
network
low complexity
themehunk CWE-79
6.1
2022-09-26 CVE-2022-2405 Missing Authorization vulnerability in Themehunk WP Popup Builder
The WP Popup Builder WordPress plugin before 1.2.9 does not have authorisation and CSRF check in an AJAX action, allowing any authenticated users, such as subscribers to delete arbitrary Popup
network
low complexity
themehunk CWE-862
4.3