Ghozylab Popup Builder vulnerabilities
3 known vulnerabilities affecting ghozylab/popup_builder.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM1UNKNOWN2
Vulnerabilities
Page 1 of 1
CVE-2025-46230UNKNOWN≤ 1.1.352025-04-24
CVE-2025-46230 CWE-98 CVE-2025-46230: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusio
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in GhozyLab Popup Builder easy-notify-lite allows PHP Local File Inclusion.This issue affects Popup Builder: from n/a through <= 1.1.35.
cvelistv5nvd
CVE-2025-26882UNKNOWN≤ 1.1.332025-02-25
CVE-2025-26882 CWE-79 CVE-2025-26882: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability i
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects Popup Builder: from n/a through <= 1.1.33.
cvelistv5nvd
CVE-2024-3236MEDIUMCVSS 5.4fixed in 1.1.332024-06-17
CVE-2024-3236 [MEDIUM] CWE-79 CVE-2024-3236: The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notificati
The Popup Builder WordPress plugin before 1.1.33 does not sanitise and escape some of its Notification fields, which could allow users such as contributor and above to perform Stored Cross-Site Scripting attacks.
nvd