Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration allows Stored XSS.This issue affects WP Modal Popup with Cookie Integration: from n/a through <= 2.4.
Published: 2025-04-01
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from the plugin's failure to properly neutralize user input when generating web pages. This leads to a stored cross‑site scripting flaw that allows an attacker to inject malicious scripts into contexts viewed by other users. An attacker who can write or modify plugin data could embed scripts that execute when legitimate visitors load the affected page, potentially enabling session hijack, credential theft, or defacement. The weakness corresponds to CWE‑79.

Affected Systems

Astoundify WP Modal Popup with Cookie Integration plugin, versions up to and including 2.4. All releases from the earliest available version through 2.4 are vulnerable until the plugin is updated beyond that point.

Risk and Exploitability

The CVSS score of 5.9 indicates a medium severity vulnerability, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploitation. The attack vector is inferred to require an attacker to submit or alter content through the plugin’s interface, indicating that users with write permissions to plugin data are the primary risk group. Although the probability of exploitation is relatively low, the impact of successful injection could compromise user sessions and site integrity, warranting prompt remediation.

Generated by OpenCVE AI on May 1, 2026 at 11:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to a version newer than 2.4
  • If an update is unavailable, disable or uninstall the plugin to remove the attack surface
  • Deploy a Content Security Policy that disallows inline script execution and limits external script sources

Generated by OpenCVE AI on May 1, 2026 at 11:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-9252 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration allows Stored XSS. This issue affects WP Modal Popup with Cookie Integration: from n/a through 2.4.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration allows Stored XSS. This issue affects WP Modal Popup with Cookie Integration: from n/a through 2.4. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration wp-modal-popup-with-cookie-integration allows Stored XSS.This issue affects WP Modal Popup with Cookie Integration: from n/a through <= 2.4.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Tue, 01 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Apr 2025 15:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Modal Popup with Cookie Integration allows Stored XSS. This issue affects WP Modal Popup with Cookie Integration: from n/a through 2.4.
Title WordPress WP Modal Popup with Cookie Integration plugin <= 2.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:12.582Z

Reserved: 2025-04-01T13:19:46.769Z

Link: CVE-2025-31772

cve-icon Vulnrichment

Updated: 2025-04-01T19:45:01.473Z

cve-icon NVD

Status : Deferred

Published: 2025-04-01T15:16:14.437

Modified: 2026-04-23T15:28:15.693

Link: CVE-2025-31772

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T12:00:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')