Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects Popup Builder: from n/a through <= 1.1.33.
Published: 2025-02-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation, allowing attackers to inject arbitrary JavaScript that is stored and served to unsuspecting users. This stored XSS flaw can lead to session hijacking, credential theft, defacement or drive‑by malware installation, affecting the confidentiality, integrity, or availability of the site’s data for any visitor that views the compromised content. The weakness is identified as CWE‑79.

Affected Systems

The affected product is the GhozyLab Popup Builder Easy‑Notify‑Lite plugin for WordPress, versions from the earliest release through 1.1.33. Users running any of those releases on a WordPress site are vulnerable.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The attack vector is inferred to be a web‑based input via the plugin’s interface that accepts unsanitized data, which is then stored and rendered back to visitors. The lack of a KEV listing means no publicly known exploit has been confirmed yet, but the stored nature of the flaw allows an attacker to propagate malicious code once injected.

Generated by OpenCVE AI on May 1, 2026 at 15:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the GhozyLab Popup Builder plugin to the latest version (1.1.34 or newer) or any release that removes the stored XSS flaw.
  • If an upgrade is not immediately possible, review and sanitize or escape all input fields handled by the plugin, and delete any stored content that may contain malicious code.
  • Temporarily disable or uninstall the Popup Builder plugin until a patched version is available to eliminate the attack surface.

Generated by OpenCVE AI on May 1, 2026 at 15:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5396 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder allows Stored XSS. This issue affects Popup Builder: from n/a through 1.1.33.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder allows Stored XSS. This issue affects Popup Builder: from n/a through 1.1.33. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder easy-notify-lite allows Stored XSS.This issue affects Popup Builder: from n/a through <= 1.1.33.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 25 Feb 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Feb 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in GhozyLab Popup Builder allows Stored XSS. This issue affects Popup Builder: from n/a through 1.1.33.
Title WordPress Popup Builder plugin <= 1.1.33 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:41.238Z

Reserved: 2025-02-17T11:50:22.449Z

Link: CVE-2025-26882

cve-icon Vulnrichment

Updated: 2025-02-25T18:51:54.412Z

cve-icon NVD

Status : Deferred

Published: 2025-02-25T15:15:24.837

Modified: 2026-06-17T09:02:32.613

Link: CVE-2025-26882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T15:30:20Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')