浏览 26+ 条来自 NVD 与 CNNVD 的 CVE 漏洞,配 AI 中文翻译、AI POC 生成、每日情报;可按厂商、产品、严重等级、CWE 检索。
| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-6443 | Essentialplugin Plugins (Various Versions) - Injected Backdoor | essentialplugin | Accordion and Accordion Slider | Critical | 9.8 | 2026-04-17 06:44:49 | Deep Dive |
| CVE-2026-4302 | WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API | wpxpo | WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation | High | 7.2 | 2026-03-21 01:24:38 | Deep Dive |
| CVE-2026-3475 | Instant Popup Builder <= 1.1.7 - Unauthenticated Arbitrary Shortcode Execution via 'token' Parameter | instantpopupbuilder | Instant Popup Builder – Powerful Popup Maker for Opt-ins, Email Newsletters & Lead Generation | Medium | 5.3 | 2026-03-19 07:34:56 | Deep Dive |
| CVE-2026-1720 | WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation | wpxpo | WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation | High | 8.8 | 2026-03-05 13:24:01 | Deep Dive |
| CVE-2025-9490 | Popup Maker <= 1.20.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via title Parameter | danieliser | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Medium | 6.4 | 2025-09-26 05:27:21 | Deep Dive |
| CVE-2025-4205 | Popup Maker <= 1.20.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via popupID Parameter | danieliser | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Medium | 6.4 | 2025-06-03 11:22:26 | Deep Dive |
| CVE-2025-24746 | WordPress Popup Maker plugin <= 1.20.2 - Cross Site Scripting (XSS) vulnerability | Daniel Iser | Popup Maker | Medium | 6.5 | 2025-01-24 17:25:23 | Deep Dive |
| CVE-2024-12411 | WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More <= 2.5.4 - Reflected Cross-Site Scripting | onetarek | WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More | Medium | 6.1 | 2024-12-14 04:23:44 | Deep Dive |
| CVE-2022-45819 | WordPress Popup Maker plugin <= 1.17.1 - Broken Access Control vulnerability | Daniel Iser | Popup Maker | Low | 3.5 | 2024-12-13 14:22:03 | Deep Dive |
| CVE-2024-10583 | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder <= 1.20.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | danieliser | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Medium | 5.4 | 2024-12-12 06:46:34 | Deep Dive |
| CVE-2024-52421 | WordPress WP Popup Window Maker plugin <= 2.0 - CSRF to Stored XSS vulnerability | wp-buy | WP Popup Window Maker | High | 7.1 | 2024-11-19 16:32:18 | Deep Dive |
| CVE-2024-47358 | WordPress Popup Maker plugin <= 1.19.2 - Broken Access Control vulnerability | Daniel Iser | Popup Maker | Medium | 5.3 | 2024-11-01 14:17:04 | Deep Dive |
| CVE-2024-5561 | Popup Maker < 1.19.1 - Admin+ Stored XSS | Unknown | Popup Maker | - | - | 2024-09-09 06:00:01 | Deep Dive |
| CVE-2024-7054 | Popup Maker <= 1.19.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | danieliser | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Medium | 6.4 | 2024-08-20 10:58:30 | Deep Dive |
| CVE-2024-34770 | WordPress Popup Maker WP plugin <= 1.3.6 - Cross Site Scripting (XSS) vulnerability | Popup Maker | Popup Maker WP | Medium | 6.5 | 2024-06-03 11:13:53 | Deep Dive |
| CVE-2024-3155 | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <= 2.2.80 - Authenticated (Contributor+) Stored Cross-Site Scripting | pickplugins | Post Grid | Medium | 6.4 | 2024-05-21 02:32:59 | Deep Dive |
| CVE-2024-0881 | Combo Blocks < 2.2.76 - Unauthenticated Password Protected Posts Access | Unknown | Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel | - | - | 2024-04-11 15:36:31 | Deep Dive |
| CVE-2024-2336 | Popup Maker – Popup for opt-ins, lead gen, & more <= 1.18.2 - Authenticated (Contributor+) Stored Cross-Site Scripting | danieliser | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | Medium | 6.4 | 2024-04-09 18:58:45 | Deep Dive |
| CVE-2023-7072 | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.68 - Information Exposure via get_posts API Endpoint | pickplugins | Post Grid | High | 7.5 | 2024-03-12 22:32:27 | Deep Dive |
| CVE-2023-6645 | Post Grid Combo – 36+ Gutenberg Blocks <= 2.2.64 - Authenticated (Contributor+) Cross-Site Scripting | pickplugins | Post Grid | Medium | 6.4 | 2024-01-11 08:32:50 | Deep Dive |