
CVE-2024-10861 – Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update
https://notcve.org/view.php?id=CVE-2024-10861
15 Nov 2024 — The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it possible for unauthenticated attackers to update the 'ays_pb_upgrade_plugin' option with arbitrary data. • https://plugins.trac.wordpress.org/browser/ays-popup-box/tags/4.9.2/admin/class-ays-pb-admin.php#L609 • CWE-862: Missing Authorization •

CVE-2024-3897 – Popup Box – Best WordPress Popup Plugin <= 4.3.6 - Missing Authorization to Information Exposure
https://notcve.org/view.php?id=CVE-2024-3897
24 Apr 2024 — The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_pb_create_author AJAX action in all versions up to, and including, 4.3.6. This makes it possible for unauthenticated attackers to enumerate all emails registered on the website. El complemento Popup Box – Best WordPress Popup Plugin para WordPress es vulnerable al acceso no autorizado a los datos debido a una falta de verificación de capacidad en la acció... • https://plugins.trac.wordpress.org/changeset/3073593/ays-popup-box/tags/4.3.7/admin/class-ays-pb-admin.php?old=3072088&old_path=ays-popup-box%2Ftags%2F4.3.6%2Fadmin%2Fclass-ays-pb-admin.php • CWE-862: Missing Authorization •

CVE-2023-5809 – Popup box < 3.8.6 - Admin+ Stored XSS in Categories
https://notcve.org/view.php?id=CVE-2023-5809
13 Nov 2023 — The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) El complemento Popup box de WordPress anterior a 3.8.6 no sanitiza ni escapa a algunas de sus configuraciones, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar ataques de Cross-Site Scri... • https://wpscan.com/vulnerability/f1eb05e8-1b7c-45b1-912d-f668bd68e265 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-5874 – Popup box < 3.8.6 - Admin+ Stored XSS in Popup Settings
https://notcve.org/view.php?id=CVE-2023-5874
13 Nov 2023 — The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) El complemento Popup box de WordPress anterior a 3.8.6 no sanitiza ni escapa a algunas de sus configuraciones, lo que podría permitir a usuarios con privilegios elevados, como el administrador, realizar ataques de Cross-Site Scri... • https://wpscan.com/vulnerability/ebe3e873-1259-43b9-a027-daa4dbd937f3 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-5343 – Popup Box < 3.7.9 - Admin+ Stored XSS
https://notcve.org/view.php?id=CVE-2023-5343
27 Oct 2023 — The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed. El complemento Popup box de WordPress anterior a 3.7.9 no sanitiza ni escapa a algunas de sus configuraciones, lo que podría permitir a usuarios con altos privilegios, como el administrador, realizar ataques de Cross Site Scripting incluso cuando unfiltered_html no está permitido. T... • https://wpscan.com/vulnerability/74613b38-48f2-43d5-bae5-25c89ba7db6e • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-4390 – Popup box < 3.7.2 - Admin+ Stored Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2023-4390
29 Aug 2023 — The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html capability is disallowed (for example in a multisite setup). El complemento Popup box de WordPress anterior a 3.7.2 no sanitiza ni escapa de algunos campos emergentes, lo que podría permitir a usuarios con altos privilegios, como un administrador, inyectar scripts web arbitrarios incluso cuand... • https://wpscan.com/vulnerability/9fd2eb81-185d-4d42-8acf-925664b7cb2f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2023-27414 – WordPress Popup box Plugin <= 3.4.4 is vulnerable to Cross Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2023-27414
08 Mar 2023 — Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions. The Popup box plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_pb_tab' parameter in versions up to, and including, 3.4.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. Unauth. • https://patchstack.com/database/vulnerability/ays-popup-box/wordpress-popup-box-plugin-3-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-0641 – Popup Like box < 3.6.1 - Reflected Cross-Site Scripting
https://notcve.org/view.php?id=CVE-2022-0641
07 Mar 2022 — The Popup Like box WordPress plugin before 3.6.1 does not sanitize and escape the ays_fb_tab parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting. El plugin Popup Like box de WordPress versiones anteriores a 3.6.1, no sanea y escapa del parámetro ays_fb_tab antes de devolverlo en una página de administración, conllevando a un problema de tipo Cross-Site Scripting Reflejado • https://wpscan.com/vulnerability/0a9830df-5f5d-40a3-9841-40994275136f • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2021-24458 – Popup box < 2.3.4 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24458
29 Jun 2021 — The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard Las funciones get_ays_popupboxes() y get_popup_categories() del plugin Popup box de WordPress versiones anteriores a 2.3.4, no usaban la lista blanca ni comprobaban el parámetro orderby antes de usarlo en las sentencias ... • https://wpscan.com/vulnerability/8a588266-54cd-4779-adcf-f9b9e226c297 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2021-24460 – Popup Like box - Page Plugin < 3.5.3 - Authenticated Blind SQL Injections
https://notcve.org/view.php?id=CVE-2021-24460
29 Jun 2021 — The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB calls, leading to SQL injection issues in the admin dashboard La función get_fb_likeboxes() del plugin de WordPress Popup Like box versiones anteriores a 3.5.3, no usaba la lista blanca ni comprobaba el parámetro orderby antes de usarlo en las sentencias SQL pasadas a las llamadas a la base d... • https://wpscan.com/vulnerability/9c0164f2-464b-4876-a48f-c0ebd63cf397 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •