This page lists publicly disclosed CVE vulnerabilities affecting accessally popupally (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2020-36875 | AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and execute arbitrary PHP in the context of the WordPress web server process, resulting in remote code execution. | [email protected] | 9.3 | 0.75% | 2026-01-09 | 2026-06-16 |
| CVE-2024-34796 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1. | [email protected] | 5.9 | 0.28% | 2024-06-03 | 2026-06-17 |
| CVE-2024-33639 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AccessAlly PopupAlly allows Stored XSS.This issue affects PopupAlly: from n/a through 2.1.1. | [email protected] | 5.9 | 0.36% | 2024-04-26 | 2026-06-17 |
| CVE-2024-23520 | Missing Authorization vulnerability in AccessAlly PopupAlly.This issue affects PopupAlly: from n/a through 2.1.0. | [email protected] | 4.3 | 0.34% | 2024-03-26 | 2026-06-17 |