Popup Maker WordPress 插件(版本 1.4.5 及更早版本)在其一个账户连接操作中未执行权限检查,仅验证了 nonce 值。因此,即使是具有最低权限的已认证用户(例如订阅者)也能覆盖网站范围内 Popup Maker 插件的配置选项(即关联的服务账户和 API 配置),而该配置本应仅由管理员才能修改。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Popup Maker | ≤ 1.4.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | Popup Maker | 0 ~ 1.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-19856 | 6.5 MEDIUM | All in One SEO < 5.0.2.1 - Unauthenticated Arbitrary Shortcode Execution via Search Query |
| CVE-2026-84740 | 6.5 MEDIUM | The Events Calendar 6.12.0 - 6.17.5 - Unauthenticated Arbitrary Shortcode Execution via 'v |
| CVE-2026-92924 | 5.4 MEDIUM | Unlimited Elements For Elementor < 2.0.21 - Subscriber+ Arbitrary Shortcode Execution via |
| CVE-2026-85005 | 5.4 MEDIUM | Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Mis |
| CVE-2026-13413 | 5.3 MEDIUM | CMP - Coming Soon & Maintenance < 4.1.20 - Unauthenticated Maintenance Mode Bypass via Log |
| CVE-2026-90952 | 5.3 MEDIUM | WP Edit Password Protected 2.0.0 - 2.0.6 - Unauthenticated Site-Wide Access Mode Bypass vi |
| CVE-2026-90987 | 5.3 MEDIUM | Easy PayPal & Stripe Buy Now Button 1.8 - 2.0.5 - Unauthenticated Payment Amount Manipulat |
| CVE-2026-91020 | 5.3 MEDIUM | WebToffee Gift Cards for WooCommerce < 1.3.1 - Unauthenticated Gift Card Amount Manipulati |
| CVE-2026-79618 | 4.3 MEDIUM | WP User Frontend < 4.3.12 - Subscriber+ Post Creation via Subscription-Gated Form |
| CVE-2026-1661 | 4.3 MEDIUM | WP Mail Logging < 1.17.0 - Unauthenticated HTML Injection |
| CVE-2026-97219 | 4.3 MEDIUM | MStore API 4.21.1 - 4.22.0 - Subscriber+ Payment Bypass via 'status' Parameter |
| CVE-2026-97317 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated reCAPTCHA Secret Key Dis | |
| CVE-2026-97318 | Giveaways and Contests by RafflePress < 1.12.27 - Unauthenticated Stored Open Redirect via | |
| CVE-2026-94298 | BuildKit < 1.0.29 - Contributor+ Stored SQLi via list_content Parameter | |
| CVE-2026-91023 | Motors – Car Dealership & Classified Listings < 1.4.124 - Subscriber+ Cross-User Post Meta | |
| CVE-2026-91022 | Motors < 1.4.124 - Listing Manager+ Stored XSS via Badge Color | |
| CVE-2026-13718 | Tabs Responsive <= 2.5 - Shop Manager+ Stored XSS via WooCommerce Product Tab Content | |
| CVE-2026-85016 | Unlimited Elements For Elementor < 2.0.21 - Contributor+ Stored XSS via Icon Library Param | |
| CVE-2026-90988 | Request a Quote <= 2.5.6 - Unauthenticated Quote Request Contact Record Disclosure via emd | |
| CVE-2026-91828 | OMGF < 6.3.11 - Unauthenticated DoS via do_optimize |
Showing top 20 of 22 CVEs. View all on vendor page → →
No comments yet