Stored Cross-Site Scripting Vulnerability in ConvertForce Popup Builder for WordPress
CVE-2025-14506
6.4MEDIUM
What is CVE-2025-14506?
The ConvertForce Popup Builder plugin for WordPress is susceptible to a Stored Cross-Site Scripting vulnerability that stems from inadequate input sanitization and output escaping methods in the Gutenberg block's entrance_animation attribute. This vulnerability allows authenticated users with Author-level access or higher to inject malicious web scripts into website pages. The injected scripts will execute when any user visits the compromised page, potentially leading to unauthorized actions and data breaches.
Affected Version(s)
ConvertForce Popup Builder 0 <= 0.0.7