
CVE-2026-3475 The Instant Popup Builder plugin for WordPress is vulnerable to Unauthenticated Arbitrary Shortcode Execution in all versions up to and including 1.1.7. This is due to … https://www.cve.org/CVERecord?id=CVE-2026-3475
Post summary
The post announces CVE-2026-3475, detailing an unauthenticated shortcode execution flaw in the Instant Popup Builder WordPress plugin up through version 1.1.7.

