No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Jun 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title field that execute when pages or posts display popup selections. | |
| Title | WordPress Popup Builder 3.49 Persistent Cross-Site Scripting | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-04T13:43:24.885Z
Reserved: 2026-06-04T11:23:41.619Z
Link: CVE-2019-25744
Updated: 2026-06-04T13:43:22.030Z
Status : Received
Published: 2026-06-04T14:16:33.717
Modified: 2026-06-04T14:16:33.717
Link: CVE-2019-25744
No data.
OpenCVE Enrichment
No data.