VendorsCode Atlanticpopup_makerall versions
Vulnerabilities

Code Atlantic Popup Maker

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

14CVEs
CVE-2024-47358
WordPress Popup Maker plugin <= 1.19.2 - Broken Access Control vulnerability
Published 2024-11-01 · Modified
9.8EPSS 0.004
CVE-2019-17574
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
Published 2019-10-14 · Modified
9.1EPSS 0.094
CVE-2022-47597
WordPress Popup Maker Plugin <= 1.17.1 is vulnerable to Sensitive Data Exposure
Published 2023-12-20 · Modified
7.5EPSS 0.006
CVE-2025-24746
WordPress Popup Maker plugin <= 1.20.2 - Cross Site Scripting (XSS) vulnerability
Published 2025-01-24 · Modified
6.5EPSS 0.003
CVE-2024-2336
Popup Maker – Popup for opt-ins, lead gen, & more <= 1.18.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-04-09 · Modified
6.4EPSS 0.003
CVE-2024-7054
Popup Maker <= 1.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-08-20 · Analyzed
6.4EPSS 0.003
CVE-2017-2284
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2017-08-02 · Modified
6.1EPSS 0.016
CVE-2022-3690
Popup Maker < 1.16.11 - Contributor+ Stored Cross Site Scripting
Published 2022-11-21 · Modified
5.5EPSS 0.007
CVE-2022-4362
Popup Maker < 1.16.9 - Contributor+ Stored XSS via Shortcode
Published 2023-01-02 · Modified
5.4EPSS 0.006
CVE-2022-4381
Popup Maker < 1.16.9 - Contributor+ Stored XSS via Subscription Form
Published 2023-01-02 · Modified
5.4EPSS 0.005
CVE-2024-10583
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Published 2024-12-12 · Analyzed
5.4EPSS 0.003
CVE-2022-1104
Popup Maker < 1.16.5 - Admin+ Stored Cross-Site Scripting
Published 2022-05-09 · Modified
4.81 PoCEPSS 0.564
CVE-2024-5561
Popup Maker < 1.19.1 - Admin+ Stored XSS
Published 2024-09-09 · Analyzed
4.8EPSS 0.005
CVE-2022-45819
WordPress Popup Maker plugin <= 1.17.1 - Broken Access Control vulnerability
Published 2024-12-13 · Modified
3.5EPSS 0.004