Unauthenticated Cross Site Scripting Vulnerability in Popup Maker by WordPress
CVE-2026-28177
7.1HIGH
What is CVE-2026-28177?
An unauthenticated Cross Site Scripting (XSS) vulnerability has been identified in the Popup Maker plugin for WordPress, affecting versions up to 1.23.0. This flaw enables attackers to inject malicious scripts into web pages, potentially leading to the exposure of sensitive user data or session hijacking when exploited. It is critical for users of the affected versions to update their plugins to mitigate the risk associated with this vulnerability.
Affected Version(s)
Popup Maker <= 1.23.0