cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2024-10583,https://securityvulnerability.io/vulnerability/CVE-2024-10583,Stored Cross-Site Scripting Vulnerability in WP Popups Builder,"The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",Wordpress,"Popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate WP Popups Builder",5.4,MEDIUM,0.00044999999227002263,false,,false,false,false,,false,false,2024-12-12T06:46:33.622Z,0 CVE-2024-7054,https://securityvulnerability.io/vulnerability/CVE-2024-7054,Stored XSS Vulnerability in WP Popups Builder,"The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.",Wordpress,"Popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate WP Popups Builder",6.4,MEDIUM,0.00044999999227002263,false,,false,false,false,,false,false,2024-08-20T10:58:30.167Z,0