VYPR

Popup Anything

by Essentialplugin

CVEs (3)

  • CVE-2022-2115MedJul 25, 2022
    risk 0.40cvss 6.1epss 0.01

    The Popup Anything WordPress plugin before 2.1.7 does not sanitise and escape a parameter before outputting it back in a frontend page, leading to a Reflected Cross-Site Scripting

  • CVE-2021-24883MedNov 29, 2021
    risk 0.35cvss 5.4epss 0.01

    The Popup Anything WordPress plugin before 2.0.4 does not escape the Link Text and Button Text fields of Popup, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks

  • CVE-2022-38077MedMar 29, 2023
    risk 0.28cvss 4.3epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability in WP OnlineSupport, Essential Plugin Popup Anything – A Marketing Popup and Lead Generation Conversions plugin <= 2.2.1 versions.