PLUGIN SECURITY

Is Popup Builder safe?

Increase Sales, Lead Generation, Conversion rates and receive good Call to Action rates with smart WordPress popup plugin.

What this plugin does

  • Slug: popup-builder
  • Author: popupbuilder
  • 200000+ active installs
  • 94/100 rating (2213 reviews on wordpress.org)
  • 12158318 all-time downloads
  • On WordPress.org since 2015-05-30

pop uppopuppopup builderpopup makerwordpress popup

Maintenance status

  • Latest known version: 4.4.5
  • Last updated: 2026-07-18 8:00am GMT
  • Tested up to WordPress: 7.0.4
  • Requires PHP: 5.3.3+

Known vulnerabilities

23 known CVEs on file for Popup Builder.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-25744 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] <= 3.49 (unfixed) Medium 5.4 < 3.49 3.49 2026-06-04 ✓ fixed in latest
CVE-2025-13079 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.4.3 Use of Predictable Algorithm in Random Number Generator Medium 5.3 < 4.4.3 4.4.3 2026-02-18 ✓ fixed in latest
CVE-2024-9428 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.3.5 4.3.5 2024-11-21 ✓ fixed in latest
CVE-2024-2541 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.7 Exposure of Sensitive Information to an Unauthorized Actor High 7.5 < 4.3.7 4.3.7 2024-08-28 ✓ fixed in latest
CVE-2024-2544 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2 Missing Authorization Medium 6.4 < 4.3.2 4.3.2 2024-06-14 ✓ fixed in latest
CVE-2023-6696 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.2 Missing Authorization High 8.1 < 4.3.2 4.3.2 2024-06-14 ✓ fixed in latest
CVE-2024-2506 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.3.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.4 < 4.3.0 4.3.0 2024-05-31 ✓ fixed in latest
CVE-2024-30184 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 4.2.7 4.2.7 2024-03-25 ✓ fixed in latest
+ 22 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6294 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.6 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 7.2 < 4.2.6 4.2.6 2024-01-17 ✓ fixed in latest
CVE-2023-6000 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 4.2.3 4.2.3 2023-12-11 ✓ fixed in latest
CVE-2023-3226 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.2.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.2.2 4.2.2 2023-08-28 ✓ fixed in latest
CVE-2022-29495 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.12 Cross-Site Request Forgery (CSRF) Medium 5.4 < 4.1.12 4.1.12 2022-06-30 ✓ fixed in latest
CVE-2022-1894 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.11 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 4.1.11 4.1.11 2022-06-20 ✓ fixed in latest
CVE-2022-32289 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.11 Cross-Site Request Forgery (CSRF) Medium 5.4 < 4.1.11 4.1.11 2022-06-17 ✓ fixed in latest
CVE-2022-0479 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 4.1.1 4.1.1 2022-03-07 ✓ fixed in latest
CVE-2022-0228 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.2 < 4.1.1 4.1.1 2022-01-24 ✓ fixed in latest
CVE-2021-25082 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.1.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.8 < 4.1.1 4.1.1 2022-01-24 ✓ fixed in latest
CVE-2021-24152 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.74 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.74 3.74 2021-02-02 ✓ fixed in latest
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72 Unknown < 3.72 3.72 2021-01-28 ✓ fixed in latest
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72 Unknown < 3.72 3.72 2021-01-28 ✓ fixed in latest
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72 Unknown < 3.72 3.72 2021-01-28 ✓ fixed in latest
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.72 Unknown < 3.72 3.72 2021-01-28 ✓ fixed in latest
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.69.7 Unknown < 3.69.7 3.69.7 2020-12-14 ✓ fixed in latest
CVE-2020-10195 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1 Exposure of Sensitive Information to an Unauthorized Actor Medium 6.3 < 3.64.1 3.64.1 2020-03-12 ✓ fixed in latest
CVE-2020-10196, CVE-2020-10195 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.64.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.64.1 3.64.1 2020-03-12 ✓ fixed in latest
CVE-2020-9006 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.0.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.0.2 3.0.2 2020-02-16 ✓ fixed in latest
CVE-2019-14695 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Critical 9.8 < 3.45 3.45 2019-08-06 ✓ fixed in latest
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 3.45 Unknown < 3.45 3.45 2019-08-06 ✓ fixed in latest
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] < 4.4.2 Medium 6.4 < 4.4.2 4.4.2 0000-00-00 ✓ fixed in latest
CVE-2025-9856 Popup Builder – Create highly converting, mobile friendly marketing popups. < 4.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting Unknown < 4.4.2 4.4.2 ✓ fixed in latest

How to fix it

Keep Popup Builder updated — 4.4.5 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.