Skip to content
Noroxi

Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

popup-builder-block · plugin

Known security vulnerabilities for Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers. Find out in seconds which version runs on your site with WP Lens.

7 known vulnerabilities

latest Feb 10, 2026

Vulnerabilities

  • CVE-2025-14314

    WordPress PopupKit plugin <= 2.1.5 - SQL Injection vulnerability

    High 8.5
  • CVE-2025-13192

    Popup builder with Gamification <= 2.2.0 - Unauthenticated SQL Injection via Multiple REST API Endpoints

    High 8.2
  • CVE-2025-10861

    Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.4 - Unauthenticated Server-Side Request Forgery

    High 7.5
  • CVE-2025-10862

    Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers <= 2.1.3 - Unauthenticated SQL Injection via 'id'

    High 7.5
  • CVE-2025-14895

    PopupKit <= 2.2.0 - Missing Authorization to Sensitive Information Disclosure and Data Deletion

    Medium 5.4
  • CVE-2025-14441

    Popupkit <= 2.2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Subscriber Data Deletion

    Medium 4.3
  • CVE-2025-69026

    WordPress PopupKit plugin <= 2.1.5 - Sensitive Data Exposure vulnerability

    Medium 4.3

← Back to directory