Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nelio Software Nelio Popups nelio-popups allows Stored XSS.This issue affects Nelio Popups: from n/a through <= 1.3.0.
Published: 2025-11-21
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Nelio Software’s Nelio Popups plugin implements a stored cross‑site scripting (XSS) flaw due to improper neutralization of input during web page generation. The vulnerability allows an attacker to embed malicious JavaScript that is persisted in the plugin’s database. When the affected content is rendered, the injected code executes in the browsers of site visitors, enabling session hijacking, credential theft, defacement, or execution of further malicious payloads. This weakness falls under CWE‑79. The impact is confined to confidentiality, integrity, and availability of web users who view the compromised pages. The description does not explicitly state the required conditions for exploitation, so it is inferred that an attacker must supply or modify content accepted by the plugin’s storage paths.

Affected Systems

WordPress sites that have installed the Nelio Popups plugin for any version up through 1.3.0 are vulnerable. Vendors and products affected are Nelio Software’s Nelio Popups. The affected version range is from an undefined earliest release through 1.3.0, inclusive. Any instance of the plugin within that range, regardless of the WordPress version, can be impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% reflects a low but non‑zero probability of actual exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, reducing its perceived immediacy but still posing a notable risk. Exploitation requires that the attacker insert malicious content into the plugin’s storage system—typically via the user‑interface that accepts popup or form data—so that the stored script is later rendered in a normal page view. Once the script is executed, an attacker can perform client‑side attacks directed at any visitor of the site.

Generated by OpenCVE AI on April 29, 2026 at 22:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Nelio Popups plugin to any version newer than 1.3.0, which contains the XSS patch.
  • If a newer version is not available, permanently disable the plugin to remove the attack surface.
  • Remove or sanitize any data that may have been stored through the plugin to eliminate already injected scripts.

Generated by OpenCVE AI on April 29, 2026 at 22:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Wed, 10 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 09:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 21 Nov 2025 12:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nelio Software Nelio Popups nelio-popups allows Stored XSS.This issue affects Nelio Popups: from n/a through <= 1.3.0.
Title WordPress Nelio Popups plugin <= 1.3.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:17.094Z

Reserved: 2025-11-21T11:21:20.345Z

Link: CVE-2025-66111

cve-icon Vulnrichment

Updated: 2025-12-10T20:49:33.177Z

cve-icon NVD

Status : Deferred

Published: 2025-11-21T13:15:52.840

Modified: 2026-04-27T18:16:36.363

Link: CVE-2025-66111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')