Vulnerabilities (CVE)

Filtered by vendor Custom Popup Builder Project Subscribe
Filtered by product Custom Popup Builder
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-28612 1 Custom Popup Builder Project 1 Custom Popup Builder 2024-11-21 3.5 LOW 5.4 MEDIUM
Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.
CVE-2022-0214 1 Custom Popup Builder Project 1 Custom Popup Builder 2024-11-21 5.0 MEDIUM 7.5 HIGH
The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog