CVE Tools

Popup Builder

25 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Popup Builder, a product in the web cms plugins space. Use it to gauge the current risk picture and drill into individual advisories.

Popup Builder CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Popup Builder CVEs per month
MonthCVEs
2024-100
2024-110
2024-121
2025-010
2025-021
2025-030
2025-041
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 25 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical312%
  • High624%
  • Medium1664%

Latest CVEs

The 15 most recently published vulnerabilities affecting Popup Builder.

  1. CVE-2019-25744WordPress Popup Builder 3.49 Persistent Cross-Site Scripting5.4
  2. CVE-2025-46230WordPress Popup Builder plugin <= 1.1.35 - Local File Inclusion Vulnerability7.5
  3. CVE-2025-26882WordPress Popup Builder plugin <= 1.1.33 - Cross Site Scripting (XSS) vulnerability6.5
  4. CVE-2024-9428Popup Builder < 4.3.5 - Admin+ Stored XSS4.8
  5. CVE-2024-2541Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File5.3
  6. CVE-2024-3602Pop ups, Exit intent popups, email popups, banners, bars, countdowns and cart savers – Promolayer <= 1.1.0 - Missing Authorization4.3
  7. CVE-2024-3236Easy Notify Lite < 1.1.33 - Contributor+ Stored XSS5.4
  8. CVE-2023-6696Popup Builder – Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure8.1
  9. CVE-2024-2544Popup Builder <= 4.3.0 - Missing Authorization in Multiple AJAX Actions7.4
  10. CVE-2024-34567WordPress Easy Notify Lite plugin <= 1.1.29 - Cross Site Scripting (XSS) vulnerability6.5
  11. CVE-2024-30184WordPress Popup Builder plugin <= 4.2.6 - Cross Site Scripting (XSS) vulnerability6.5
  12. CVE-2023-6294popup-builder < 4.2.6 - Admin+ SSRF & File Read7.2
  13. CVE-2023-6000Popup Builder < 4.2.3 - Unauthenticated Stored XSS6.1
  14. CVE-2023-3226Popup Builder < 4.2.0 - Admin+ Stored Cross-Site Scripting4.8
  15. CVE-2022-29495WordPress Popup Builder plugin <= 4.1.11 - Cross-Site Request Forgery (CSRF) leading to plugin settings update5.4

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store