VYPR

Instant Popup Builder

by WordPress

CVEs (1)

  • CVE-2026-3475MedMar 19, 2026
    risk 0.34cvss 5.3epss 0.00

    The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to the handle_email_verification_page() function constructing a shortcode string from user-supplied GET parameters…