Plugin Vulnerability Hub
Plugin 23 known issues Latest disclosed Feb 18, 2026

Popup Builder – Create highly converting, mobile friendly marketing popups. Vulnerabilities

Review known vulnerability records for the WordPress plugin Popup Builder – Create highly converting, mobile friendly marketing popups. (`popup-builder`), including severity, CVE references, affected versions, and patch status.

Known Records
23
High or Critical
9
Linked CVEs
22
Last Updated
Feb 19, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Popup Builder – Create highly converting, mobile friendly marketing popups. so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
23 records include a published patch path.
Severity Mix
3 critical and 6 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for Popup Builder – Create highly converting, mobile friendly marketing popups.

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2025-13079
Popup Builder - Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. Th...

Published
Feb 18, 2026
Patched Release
4.4.3
Affected Versions
Versions up to 4.4.2
Next Step
Update to 4.4.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9856
Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sg_popup' shortcode in all versions up to, and including, 4.4.1 due to insufficient input sanitization and output es...

Published
Dec 12, 2025
Patched Release
4.4.2
Affected Versions
Versions up to 4.4.1
Next Step
Update to 4.4.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9428
Popup Builder <= 4.3.4 - Authenticated (Admin+) Stored Cross-Site Scripting

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.3.4 due to insufficient input sanitization and output escaping. This makes...

Published
Nov 21, 2024
Patched Release
4.3.5
Affected Versions
Versions up to 4.3.4
Next Step
Update to 4.3.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2541
Popup Builder <= 4.3.6 - Sensitive Information Exposure via Imported Subscribers CSV File

The Popup Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.3.6 via the Subscribers Import feature. This makes it possible for unauthenticated attackers to extract sensitive data after an administrator has importe...

Published
Aug 28, 2024
Patched Release
4.3.7
Affected Versions
Versions up to 4.3.6
Next Step
Update to 4.3.7 or newer if supported.
Plugin High Patched: Yes CVE-2023-6696
Popup Builder – Create highly converting, mobile friendly marketing popups <= 4.3.1 - Missing Authorization and Nonce Exposure

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to unauthorized access of functionality due to a missing capability check on several functions in all versions up to, and including, 4.3.1. While some functions cont...

Published
Jun 14, 2024
Patched Release
4.3.2
Affected Versions
Versions up to 4.3.1
Next Step
Update to 4.3.2 or newer if supported.
Plugin High Patched: Yes CVE-2024-2544
Popup Builder <= 4.3.0 - Missing Authorization in Multiple AJAX Actions

The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform multiple unauth...

Published
Jun 14, 2024
Patched Release
4.3.2
Affected Versions
Versions up to 4.3.0
Next Step
Update to 4.3.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-2506
Popup Builder <= 4.2.7 - Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JS functionality in all versions up to, and including, 4.2.7 due to insufficient input sanitization and output escaping...

Published
May 31, 2024
Patched Release
4.3.0
Affected Versions
Versions up to 4.2.7
Next Step
Update to 4.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-30184
Popup Builder <= 4.2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sg_popup shortcode in all versions up to, and including, 4.2.6 due to insufficient input sanitization and output esca...

Published
Mar 25, 2024
Patched Release
4.2.7
Affected Versions
Versions up to 4.2.6
Next Step
Update to 4.2.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6294
Popup Builder <= 4.2.5 - Authenticated (Admin+) Server-Side Request Forgery

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.2.5. This makes it possible for authenticated attackers, with administrator-level access and a...

Published
Jan 17, 2024
Patched Release
4.2.6
Affected Versions
Versions up to 4.2.5
Next Step
Update to 4.2.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6000
Popup Builder <= 4.2.2 - Unauthenticated Stored Cross-Site Scripting

The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via popups in versions up to 4.2.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that wi...

Published
Dec 11, 2023
Patched Release
4.2.3
Affected Versions
Versions before 4.2.3
Next Step
Update to 4.2.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-3226
Popup Builder <= 4.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting

The Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.2.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level...

Published
Aug 28, 2023
Patched Release
4.2.2
Affected Versions
Versions up to 4.2.1
Next Step
Update to 4.2.2 or newer if supported.
Plugin High Patched: Yes CVE-2022-29495
Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.1.11 - Cross-Site Request Forgery to Settings Update

The "Popup Builder – Create highly converting, mobile friendly marketing popups." plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.11. This is due to missing or incorrect nonce validation on the saveSettings() function. This m...

Published
Jun 30, 2022
Patched Release
4.1.12
Affected Versions
Versions up to 4.1.11
Next Step
Update to 4.1.12 or newer if supported.