VYPR

Custom Popup Builder

by WordPress

CVEs (2)

  • CVE-2022-0214HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.02

    The Custom Popup Builder WordPress plugin before 1.3.1 autoload data from its popup on every pages, as such data can be sent by unauthenticated user, and is not validated in length, this could cause a denial of service on the blog

  • CVE-2022-28612MedJun 15, 2022
    risk 0.35cvss 5.4epss 0.00

    Improper Access Control vulnerability leading to multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Muneeb's Custom Popup Builder plugin <= 1.3.1 at WordPress.