PT-2026-20591 · WordPress · Popup Builder

Rafshanzani Suhada

·

Published

2026-02-19

·

Updated

2026-02-23

·

CVE-2025-13079

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Popup Builder – Create highly converting, mobile friendly marketing popups. versions prior to 4.4.3
Description The Popup Builder plugin for WordPress is susceptible to authorization bypass. This occurs because the plugin generates predictable unsubscribe tokens using deterministic data. An unauthenticated attacker can unsubscribe arbitrary subscribers from mailing lists by brute-forcing the unsubscribe token, provided they know the victim's email address.
Recommendations Versions prior to 4.4.3 should be updated.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-13079

Affected Products

Popup Builder