Stored Cross-Site Scripting in Advanced Popups Plugin for WordPress
CVE-2026-11996

6.4MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 September 2026

What is CVE-2026-11996?

The Advanced Popups plugin for WordPress has a vulnerability due to insufficient input sanitization and output escaping in the 'Notification Button Link' field. Authenticated attackers with author-level access can exploit this flaw to inject arbitrary web scripts. This can lead to malicious scripts executing on pages viewed by users, compromising their security and data integrity. Immediate action is recommended to protect against potential exploitation.

Affected Version(s)

Advanced Popups 0 <= 1.2.3

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Cong Quang
.