Popup Maker <= 1.20.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder
Minimum safe version
1.21.0
Update to 1.21.0 or later to address 22 fixable vulnerabilities
Popup Maker <= 1.20.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via popupID Parameter
CVE-2025-24746
CVE-2024-10583
CVE-2024-47358
CVE-2024-5561
CVE-2024-7054
CVE-2024-2336
WordPress Popup Maker Plugin <= 1.9.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2022-45819
CVE-2022-47597
WordPress Popup Maker Plugin <= 1.18.0 is vulnerable to Cross Site Request Forgery (CSRF)
Popup Maker <= 1.18.0 - Cross-Site Request Forgery via init
WordPress Popup Maker Plugin < 1.16.9 is vulnerable to Cross Site Scripting (XSS)
WordPress Popup Maker Plugin < 1.16.9 is vulnerable to Cross Site Scripting (XSS)
Freemius SDK <= 2.2.3 - Missing Authorization to Arbitrary Options Update
Popup Maker <= 1.16.8 - Authenticated (Contributor+) Cross-Site Scripting
CVE-2022-3690
Freemius Library < 2.2.4 - Subscriber+ Arbitrary Option Update
CVE-2022-1104
CVE-2017-2284
CVE-2019-17574