Ays-pro
Ays-pro Popup BOX: vulnerabilidades y CVE
Ays-pro Popup BOX tiene 10 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE10
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-15611 | Media (5.4) | 0.14% | — | 7 abr 2026 | The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery… |
| CVE-2024-9599 | Media (5.4) | 0.33% | — | 15 may 2025 | The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2023-6591 | Media (4.8) | 0.48% | — | 12 feb 2024 | The Popup Box WordPress plugin before 20.9.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is… |
| CVE-2023-5874 | Media (4.8) | 0.45% | — | 4 dic 2023 | The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2023-5809 | Media (4.8) | 0.45% | — | 4 dic 2023 | The Popup box WordPress plugin before 3.8.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the… |
| CVE-2023-5343 | Media (4.8) | 0.45% | — | 20 nov 2023 | The Popup box WordPress plugin before 3.7.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is… |
| CVE-2023-4390 | Media (4.8) | 0.40% | — | 31 oct 2023 | The Popup box WordPress plugin before 3.7.2 does not sanitize and escape some Popup fields, which could allow high-privilege users such as an administrator to inject arbitrary web scripts even when the unfiltered_html… |
| CVE-2023-27414 | Media (6.1) | 0.41% | — | 21 jun 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Popup Box Team Popup box plugin <= 3.4.4 versions. |
| CVE-2021-24460 | Alta (8.8) | 1.4% | — | 2 ago 2021 | The get_fb_likeboxes() function in the Popup Like box – Page Plugin WordPress plugin before 3.5.3 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the get_results() DB… |
| CVE-2021-24458 | Alta (8.8) | 1.4% | — | 2 ago 2021 | The get_ays_popupboxes() and get_popup_categories() functions of the Popup box WordPress plugin before 2.3.4 did not use whitelist or validate the orderby parameter before using it in SQL statements passed to the… |