ConvertPlus
Brainstorm Force · 5 CVEs
CVE-2026-87741
HIGH
ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' Parameter
Sep 28, 2026
CVE-2024-13800
HIGH
Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Optio…
Feb 12, 2025
CVE-2024-4838
HIGH
ConvertPlus <= 3.5.26 - Authenticated (Contributor+) PHP Object Injection
May 16, 2024
CVE-2024-3240
HIGH
ConvertPlug <= 3.5.25 - Authenticated (Contributor+) PHP Object Injection
May 4, 2024
CVE-2024-3237
MEDIUM
ConvertPlug <= 3.5.25 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update
May 4, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-87741 | ConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' Parameter | HIGH | 0.40% | Sep 28, 2026 |
| CVE-2024-13800 | Popup Plugin For WordPress - ConvertPlus <= 3.5.30 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update | HIGH | 0.47% | Feb 12, 2025 |
| CVE-2024-4838 | ConvertPlus <= 3.5.26 - Authenticated (Contributor+) PHP Object Injection | HIGH | 0.59% | May 16, 2024 |
| CVE-2024-3240 | ConvertPlug <= 3.5.25 - Authenticated (Contributor+) PHP Object Injection | HIGH | 0.77% | May 4, 2024 |
| CVE-2024-3237 | ConvertPlug <= 3.5.25 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update | MEDIUM | 0.37% | May 4, 2024 |
Showing 1 to 5 of 5 CVEs