Stored Cross-Site Scripting in Popup Maker Plugin for WordPress
CVE-2026-15797

6.4MEDIUM

What is CVE-2026-15797?

The Popup Maker plugin for WordPress has a vulnerability that allows authenticated users with contributor-level access and above to exploit stored cross-site scripting via the post title input. This flaw stems from inadequate input sanitization and output escaping, enabling attackers to embed arbitrary web scripts into posts. The vulnerability occurs when an attacker crafts a post title with an HTML entity-encoded payload, which bypasses the intended security measures during the save process. Once rendered, this payload executes in the browser context whenever a user visits the affected page, resulting in potential data theft or further attacks. It is crucial for WordPress administrators to update to version 1.25.0 or above to mitigate this risk.

Affected Version(s)

Popup Maker – Boost Sales, Con, Optins, Subscribers with the Ultimate WP Popup Builder 0 <= 1.24.0

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

UKO
.