CVE-2024-9061: Themehunk Wp Popup Builder

Critical severity, CVSS 9.8. EPSS: 52.3% chance of exploitation in the next 30 days.

The The WP Popup Builder – Popup Forms and Marketing Lead Generation plugin for WordPress is vulnerable to arbitrary shortcode execution via the wp_ajax_nopriv_shortcode_Api_Add AJAX action in all versions up to, and including, 1.3.5. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. NOTE: This vulnerability was partially fixed in version 1.3.5 with a nonce check, which effectively prevented access to the affected function. However, version 1.3.6 incorporates the correct authorization check to prevent unauthorized access.

Affected products

  • Themehunk Wp Popup Builder: before 1.3.6 (fixed in 1.3.6)

Published 2024-10-16. Last modified 2026-06-17.