Impact
The vulnerability affects the Popup Maker WordPress plugin. An authenticated user with contributor or higher privilege can create or edit a post whose title is stored without proper sanitization. The plugin decodes the title when rendering through the Select2 component, allowing an attacker to embed malicious script that runs in the browsers of anyone who views the affected post. This stored XSS can be used to hijack sessions, deface, or steal cookies. The weakness is a classic input validation flaw, identified by CWE‑79.
Affected Systems
Affected vendors and products include the WordPress plugin Popup Maker by danieliser, which is used to boost sales, conversions, opt‑ins, and subscribers. Any installation of Popup Maker version 1.24.0 or earlier is vulnerable. No other versions are reported to be affected. WordPress sites that install the plugin and allow users with contributor or higher roles to manage content are at risk.
Risk and Exploitability
The CVSS base score of 6.4 indicates a moderate risk. The EPSS score of <1% suggests that exploitation in the wild is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, meaning no known large‑scale exploits have been registered against it. Attackers need only a contributor‑level account and the ability to create a post; the payload is injected into the post title, which is then rendered by the front‑end. If an attacker can get users to view the malicious post, the XSS will execute in their browsers.
OpenCVE Enrichment