CVE 5.3 MEDIUM

Popup Builder – Create highly converting, mobile friendly marketing popups. <= 4.4.2 - Improper Authorization to Unauthenticated Subscriber Removal via Predictable Tokens_CVE-2025-13079

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Description

The Popup Builder – Create highly converting, mobile friendly marketing popups. plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.4.2. This is due to the plugin generating predictable unsubscribe tokens using deterministic data. This makes it possible for unauthenticated attackers to unsubscribe arbitrary subscribers from mailing lists via brute-forcing the unsubscribe token, granted they know the victim's email address

Basic Information

ID CVE-2025-13079
Source Wordfence
Published Feb 19, 2026 at 03:25

Affected Product

Vendor popupbuilder
Product Popup Builder – Create highly converting, mobile friendly marketing popups.
Version *
Affected Versions popupbuilder Popup Builder – Create highly converting, mobile friendly marketing popups. *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.