Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Security & Risk Analysis

wordpress.org/plugins/sumome

Sumo is trusted by over 600,000 businesses — small and large — in growing their email lists, customer base, and revenue online.

20K active installs v1.44 PHP 7.0+ WP 4.7+ Updated Jun 5, 2025
analyticsecommerceemailleadsmarketing
100
A · Safe
CVEs total1
Unpatched0
Last CVEApr 5, 2024
Safety Verdict

Is Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Safe to Use in 2026?

Generally Safe

Score 100/100

Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Apr 5, 2024Updated 11mo ago
Risk Assessment

The Sumome plugin v1.44 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and has no reported unpatched vulnerabilities, indicating active maintenance or a lack of recent critical flaws. The absence of dangerous functions and external HTTP requests further strengthens its security profile. However, significant concerns arise from its attack surface. With a total of 9 AJAX handlers, 7 of which lack authentication checks, there is a substantial opportunity for unauthorized actions if these handlers are exploitable. The taint analysis, while limited in scope, revealed one flow with an unsanitized path, which could potentially lead to vulnerabilities if further investigation uncovers exploitable paths. The plugin's vulnerability history, though showing only medium-severity issues in the past, is a reminder that even well-maintained plugins can have weaknesses. The presence of past CSRF vulnerabilities, though currently patched, warrants continued vigilance, especially concerning any new AJAX handlers without proper CSRF protection.

Key Concerns

  • AJAX handlers without auth checks
  • Flows with unsanitized paths
  • Medium severity vulnerability in history
  • File operations present
  • Missing nonce checks on AJAX
Vulnerabilities
1 published

Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-31265medium · 4.3Cross-Site Request Forgery (CSRF)

Sumo <= 1.34 - Cross-Site Request Forgery

Apr 5, 2024 Patched in 1.35 (7d)
Version History

Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Release Timeline

v1.44Current
v1.43
v1.42
v1.41
v1.40
v1.35
v1.341 CVE
v1.33.11 CVE
v1.331 CVE
v1.321 CVE
v1.311 CVE
v1.301 CVE
Code Analysis
Analyzed Mar 16, 2026

Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
83 escaped
Nonce Checks
0
Capability Checks
1
File Operations
3
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped100 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<landing> (views\landing.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Attack Surface

Entry Points9
Unprotected7

AJAX Handlers 9

authwp_ajax_sumome_mainclasses\class_sumome.php:11
authwp_ajax_sumome_dashboard_welcomeclasses\class_sumome.php:12
authwp_ajax_sumome_hide_dashboard_overlayclasses\class_sumome.php:13
noprivwp_ajax_sumo_get_woocommerce_cart_subtotalclasses\class_sumome.php:27
noprivwp_ajax_sumo_add_woocommerce_couponclasses\class_sumome.php:31
noprivwp_ajax_sumo_remove_woocommerce_couponclasses\class_sumome.php:32
authwp_ajax_sumo_get_woocommerce_cart_subtotalclasses\class_sumome.php:34
authwp_ajax_sumo_add_woocommerce_couponclasses\class_sumome.php:35
authwp_ajax_sumo_remove_woocommerce_couponclasses\class_sumome.php:36
WordPress Hooks 8
actionwp_footerclasses\class_sumome.php:14
actionadmin_footerclasses\class_sumome.php:15
actionadmin_menuclasses\class_sumome.php:16
actionadmin_initclasses\class_sumome.php:17
actionadmin_enqueue_scriptsclasses\class_sumome.php:18
actionwp_dashboard_setupclasses\class_sumome.php:19
actionwp_footerclasses\class_sumome.php:22
actionadmin_footerclasses\class_sumome.php:24
Maintenance & Trust

Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 5, 2025
PHP min version7.0
Downloads2.5M

Community Trust

Rating84/100
Number of ratings519
Active installs20K
Developer Profile

Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation Developer Profile

Sumo

1 plugin · 20K total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sumome/js/sumome-admin.js/wp-content/plugins/sumome/css/sumome-admin.css

HTML / DOM Fingerprints

CSS Classes
sumome-site-id
Data Attributes
data-sumo-site-id
JS Globals
sumome_generate_site_idWP_Plugin_SumoMe
REST Endpoints
/wp-json/sumome/
FAQ

Frequently Asked Questions about Website Pop-up Builder by BDOW! (formerly Sumo): Pop-ups + forms for email opt-ins and lead generation