Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Popup Builder – Create highly converting, mobile friendly marketing popups.
Minimum safe version
4.4.3
Update to 4.4.3 or later to address 28 fixable vulnerabilities
CVE-2025-13079
CVE-2024-9428
CVE-2024-2541
CVE-2023-6696
CVE-2024-2544
WordPress Popup Builder Plugin <= 4.2.7 is vulnerable to Cross Site Scripting (XSS)
CVE-2024-30184
CVE-2023-6294
CVE-2023-6000
WordPress Popup Builder Plugin <= 4.1.15 is vulnerable to Cross Site Scripting (XSS)
Popup Builder <= 3.72 Missing Authorization on AJAX actions
CVE-2022-29495
CVE-2022-1894
CVE-2022-32289
WordPress Popup Builder plugin <= 3.44 - SQL Injection (SQLi) vulnerability
WordPress Popup Builder plugin <= 3.69.6 - Multiple Stored Cross-Site Scripting (XSS) vulnerabilities
WordPress Popup Builder plugin <= 3.71 - Authenticated Newsletter Send With Custom Content And Sender vulnerability
WordPress Popup Builder plugin <= 3.71 - Authenticated Deleting/Importing Subscribers vulnerability
WordPress Popup Builder plugin <= 3.71 - Authenticated Local File Inclusion (LFI) vulnerability
CVE-2022-0479
CVE-2019-14695
CVE-2020-9006
CVE-2020-10196
CVE-2020-10195
CVE-2021-24152
CVE-2021-25082
CVE-2022-0228