Impact
The Advanced Popups plugin for WordPress contains a stored cross‑site scripting flaw in the 'Notification Button Link' field. Attacks require the user to be logged in with author privileges or higher, and allow the injection of arbitrary JavaScript that is rendered whenever the link is accessed. The flaw is caused by insufficient input sanitization and output escaping, which enables the attacker to deliver malicious scripts that run in the context of any site visitor.
Affected Systems
All installations of Advanced Popups for WordPress through version 1.2.3 are affected. The vulnerability exists in the plugin regardless of site configuration, as it is triggered by any stored notification button link entered by an author or higher level user.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate severity. With an EPSS score of less than 1%, the likelihood of exploitation in the wild is currently low, and the vulnerability is not listed in CISA KEV. Attackers must first gain author or higher credentials on the WordPress site, then create or modify a notification button with a malicious link that stores the payload. Any user who visits the page containing the link will execute the injected script, potentially allowing session hijacking, credential theft, or further site compromise.
OpenCVE Enrichment