VYPR

PopupKit

by WordPress

Source repositories

CVEs (3)

  • CVE-2025-14895MedFeb 10, 2026
    risk 0.28cvss 5.4epss 0.00

    The PopupKit plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.2.0. This is due to the plugin not properly verifying that a user is authorized to access the /popup/logs REST API endpoint. This makes it possible for authenticated…

  • CVE-2025-14441MedJan 6, 2026
    risk 0.28cvss 4.3epss 0.00

    The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on the DELETE `/subscribers` REST API endpoint in all versions up to, and including, 2.2.0. This is due to the `permission_callback` only validating wp_rest nonce…

  • CVE-2025-69026MedDec 30, 2025
    risk 0.28cvss 4.3epss 0.00

    Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roxnor PopupKit popup-builder-block allows Retrieve Embedded Sensitive Data.This issue affects PopupKit: from n/a through <= 2.1.5.