Vulnerabilities

Summary — last 7 days

New vulnerabilities2,838▲ 84 vs. last week
Critical / high1,318▼ 204 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)246▲ 228 vs. last week
–

2 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.4)0.22%—Popup Maker WPAI10/2/202610/2/2026
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables…
DeferredMedium (6.5)0.26%—Popup Maker WPAI6/3/20246/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker WP popup-maker-wp allows Stored XSS.This issue affects Popup Maker WP: from n/a through <= 1.3.6.
Orbitaley — Vulnerabilities