Known vulnerabilities in the Popups plugin
7 security advisories have been published for the Popups plugin. Each entry below states what an attacker can do, what privilege they need, and the version the issue was fixed in.
- Popups - Broken Access Control (CVE-2026-2263) MEDIUM
- Popups - Remote Code Execution (CVE-2026-0911) HIGH
- Popups - Broken Access Control (CVE-2024-10580) MEDIUM
- Popups - Broken Access Control (CVE-2024-10579) MEDIUM
- Popups - Information Disclosure (CVE-2024-0368) HIGH
- Popups - Cross-Site Scripting (XSS) (CVE-2023-4961) MEDIUM
- Popups - Cross-Site Scripting (XSS) (CVE-2022-2305) MEDIUM