I13websolution
I13websolution Email Subscription Popup: vulnerabilidades y CVE
I13websolution Email Subscription Popup tiene 7 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses1
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-49912 | Media (5.9) | 0.29% | — | 22 oct 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nks Email Subscription Popup email-subscribe allows Stored XSS.This issue affects Email Subscription Popup: from n/a… |
| CVE-2025-24587 | Alta (7.6) | 32% | — | 24 ene 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Nks Email Subscription Popup email-subscribe allows Blind SQL Injection.This issue affects Email Subscription Popup:… |
| CVE-2024-11195 | Media (6.4) | 0.37% | — | 19 nov 2024 | The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including, 1.2.22 due to insufficient input… |
| CVE-2024-27960 | Media (6.1) | 0.33% | — | 17 mar 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in I Thirteen Web Solution Email Subscription Popup allows Stored XSS.This issue affects Email Subscription Popup: from… |
| CVE-2023-6555 | Media (6.1) | 0.44% | — | 8 ene 2024 | The Email Subscription Popup WordPress plugin before 1.2.20 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high… |
| CVE-2023-6527 | Media (6.1) | 0.37% | — | 6 dic 2023 | The Email Subscription Popup plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the HTTP_REFERER header in all versions up to, and including, 1.2.18 due to insufficient input sanitization and… |
| CVE-2023-30489 | Media (6.1) | 0.41% | — | 14 ago 2023 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in I Thirteen Web Solution Email Subscription Popup plugin <= 1.2.16 versions. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de I13websolution
Thumbnail Carousel Slider · 5Team Circle Image Slider With Lightbox · 4Video Carousel Slider With Lightbox · 4Thumbnail Slider With Lightbox · 4Easy Testimonial Slider AND Form · 3WP Responsive Tabs · 3Responsive Filterable Portfolio · 3WP Responsive Tabs Horizontal Vertical AND Accordion Tabs · 2Photo Gallery Slideshow & Masonry Tiled Gallery · 2Video Gallery · 2Video Grid · 2Wordpress Vertical Image Slider · 2