CVE-2024-5799: Cminds Cm Popup

Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The CM Pop-Up Banners for WordPress plugin before 1.7.3 does not sanitise and escape some of its popup fields, which could allow high privilege users such as Contributors to perform Cross-Site Scripting attacks.

Affected products

  • Cminds Cm Popup: before 1.7.3 (fixed in 1.7.3)

Published 2024-09-12. Last modified 2026-06-17.