Stored Cross-Site Scripting in Popup Maker Plugin for WordPress
CVE-2026-15797
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 18 September 2026
What is CVE-2026-15797?
The Popup Maker plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to exploit stored cross-site scripting via the post title input. This flaw stems from inadequate input sanitization and output escaping, enabling attackers to embed arbitrary web scripts into posts. The vulnerability occurs when an attacker crafts a post title with an HTML entity-encoded payload, which bypasses the intended security measures during the save process. Once rendered, this payload executes in the browser context whenever a user visits the affected page, resulting in potential data theft or further attacks. It is crucial for WordPress administrators to update to version 1.25.0 or above to mitigate this risk.
Affected Version(s)
Popup Maker β Boost Sales, Con, Optins, Subscribers with the Ultimate WP Popup Builder 0 <= 1.24.0