Description
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component.
Published: 2026-09-18
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability affects the Popup Maker WordPress plugin. An authenticated user with contributor or higher privilege can create or edit a post whose title is stored without proper sanitization. The plugin decodes the title when rendering through the Select2 component, allowing an attacker to embed malicious script that runs in the browsers of anyone who views the affected post. This stored XSS can be used to hijack sessions, deface, or steal cookies. The weakness is a classic input validation flaw, identified by CWE‑79.

Affected Systems

Affected vendors and products include the WordPress plugin Popup Maker by danieliser, which is used to boost sales, conversions, opt‑ins, and subscribers. Any installation of Popup Maker version 1.24.0 or earlier is vulnerable. No other versions are reported to be affected. WordPress sites that install the plugin and allow users with contributor or higher roles to manage content are at risk.

Risk and Exploitability

The CVSS base score of 6.4 indicates a moderate risk. The EPSS score of <1% suggests that exploitation in the wild is unlikely at present. The vulnerability is not listed in the CISA KEV catalog, meaning no known large‑scale exploits have been registered against it. Attackers need only a contributor‑level account and the ability to create a post; the payload is injected into the post title, which is then rendered by the front‑end. If an attacker can get users to view the malicious post, the XSS will execute in their browsers.

Generated by OpenCVE AI on September 19, 2026 at 19:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Popup Maker to version 1.25.0 or later to remove the input‑validation flaw
  • Sanitize or delete existing post titles that may contain script payloads and rebuild the affected database entries
  • Restrict contributor accounts to trusted users only and reduce editing privileges where possible
  • Deploy a web application firewall rule to block XSS payloads and monitor for suspicious admin activity

Generated by OpenCVE AI on September 19, 2026 at 19:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Danieliser
Danieliser popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder
Wordpress
Wordpress wordpress
Vendors & Products Danieliser
Danieliser popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder
Wordpress
Wordpress wordpress

Fri, 18 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component.
Title Popup Maker <= 1.24.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via post_title
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:21:50.937Z

Reserved: 2026-07-14T20:23:01.788Z

Link: CVE-2026-15797

cve-icon Vulnrichment

Updated: 2026-09-19T14:12:40.336Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T10:17:06.133

Modified: 2026-09-19T15:16:58.477

Link: CVE-2026-15797

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')