CVE Database /
CVE-2025-13079
CVE · Medium
CVE-2025-13079 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.4.3
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13079
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.4.3 |
Use of Predictable Algorithm in Random Number Generator |
Medium
5.3
|
< 4.4.3
|
4.4.3 |
2026-02-18 |
—
|
CVE-2025-13079
The Popup Builder plugin for WordPress contains a flaw in its handling of unsubscribe tokens, which can be guessed by an attacker with knowledge of a subscriber's email address. This weakness allows unauthorized individuals to remove any user from mailing lists without proper authentication. The issue affects all versions up to and including 4.4.2.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings