Cross-site Scripting Vulnerability in Popup Maker by WordPress
CVE-2025-24746
6.5MEDIUM
Key Information:
- Vendor
- Popup Maker
- Status
- Popup Maker
- Vendor
- CVE Published:
- 24 January 2025
Summary
A Cross-site Scripting (XSS) vulnerability in Popup Maker allows attackers to inject malicious scripts into web pages. This flaw can lead to the storage of harmful code that executes when users interact with affected popups. Specifically, this issue impacts Popup Maker from its initial release up to version 1.20.2, posing significant risks to web application security. Website administrators are advised to apply patches or updates to mitigate the risk associated with this vulnerability.
Affected Version(s)
Popup Maker <= 1.20.2
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
savphill (Patchstack Alliance)