Pricing
Case studies
Login
Start trial
Popup Builder
popupbuilder
Developer
4.4.3
Latest version
200,000
Installations
No date
Last updated
WordPress Plugin
No VDP
See changelog
Claim ownership
Report vulnerability
Vulnerabilities
Security Contributors
Vulnerability history
0 present
23 patched
7 Mitigation rules
Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens vulnerability
<= 4.4.2
18/02/2026
Authenticated (Contributor+) Stored Cross-Site Scripting vulnerability
<= 4.4.1
13/12/2025
Admin+ Stored XSS vulnerability
< 4.3.5
12/12/2024
Sensitive Information Exposure via Imported Subscribers CSV File vulnerability
<= 4.3.6
29/08/2024
Missing Authorization and Nonce Exposure vulnerability
<= 4.3.1
14/06/2024
Missing Authorization in Multiple AJAX Actions vulnerability
<= 4.3.0
14/06/2024
Authenticated(Contributor+) Stored Cross-Site Scripting via Custom JS vulnerability
<= 4.2.7
03/06/2024
Cross Site Scripting (XSS) vulnerability
<= 4.2.6
25/03/2024
Admin+ SSRF & File Read vulnerability
< 4.2.6
13/02/2024
Unauthenticated Stored XSS vulnerability
< 4.2.3
12/12/2023
Admin+ Stored Cross-Site Scripting vulnerability
< 4.2.2
26/09/2023
Cross-Site Request Forgery (CSRF) leading to plugin settings update
<= 4.1.11
30/06/2022
Authenticated Stored Cross-Site Scripting (XSS) vulnerability
<= 4.1.10
20/06/2022
Cross-Site Request Forgery (CSRF) vulnerability leading to Popup Status Change
<= 4.1.0
17/06/2022
SQL Injection (SQLi) vulnerability to Reflected Cross-Site Scripting (XSS)
<= 4.1.0
07/03/2022
Local File Inclusion (LFI) leading to Remote Code Execution (RCE)
<= 4.0.6
24/01/2022
SQL Injection (SQLi) vulnerability
<= 4.0.6
24/01/2022
Authenticated Local File Inclusion (LFI) vulnerability
<= 3.71
28/01/2021
Authenticated Deleting/Importing Subscribers vulnerability
<= 3.71
28/01/2021
Authenticated Newsletter Send With Custom Content And Sender vulnerability
<= 3.71
28/01/2021
Multiple Stored Cross-Site Scripting (XSS) vulnerabilities
<= 3.69.6
14/12/2020
SQL injection (SQLi) vulnerability
<= 2.6.7.6
16/02/2020
SQL Injection (SQLi) vulnerability
<= 3.44
06/08/2019