WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers

High-converting popup campaigns with PopupKit – advanced triggers, A/B testing, spin-to-win, multistep popups & 270+ popup templates for WordPress

7Reported vulnerabilities
8.2Highest CVSS score
2.3.3Latest version
70,000+Active installs

What to do now

Update Popup builder with Gamification, Multi-Step Popups, Page-Level Targeting, and WooCommerce Triggers to 2.2.1 or later. 7 of these have a fixed version available. Updating resolves them.

Plugin last updated: July 26, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-13192 High 8.2 0.4% 0 to 2.2.0 (inclusive) 2.2.1 February 5, 2026
CVE-2025-10861 High 7.5 0.4% 0 to 2.1.4 (inclusive) 2.1.5 October 24, 2025
CVE-2025-10862 High 7.5 0.4% 0 to 2.1.3 (inclusive) 2.1.4 October 9, 2025
CVE-2025-14314 Medium 6.5 0.4% 2.1.5 and earlier 2.2.0 November 21, 2025
CVE-2025-14895 Medium 5.4 0.3% 0 to 2.2.0 (inclusive) 2.2.1 February 10, 2026
CVE-2025-14441 Medium 4.3 0.2% 0 to 2.2.0 (inclusive) 2.2.1 January 6, 2026
CVE-2025-69026 Medium 4.3 0.2% 2.1.5 and earlier 2.2.1 December 29, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.