Impact
Unauthenticated Cross Site Scripting occurs in the Popup Maker plugin through version 1.23.0, allowing an attacker to inject malicious JavaScript that runs in the browsers of any user who views a popup. The flaw is identified as CWE-79 and can lead to session hijacking, data theft, or defacement of site content, without requiring special privileges.
Affected Systems
The vulnerability affects the WordPress Popup Maker plugin developed by Daniel Iser, specifically all releases up to and including 1.23.0. Users who have installed older versions should upgrade to version 1.24.0 or later to remediate the flaw.
Risk and Exploitability
The CVSS score of 7.1 indicates a moderate to high risk level, yet the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers can likely exploit the flaw by crafted popup content or by input fields that are not properly sanitized, gaining an unauthenticated vector to execute arbitrary code in the victim’s browser.
OpenCVE Enrichment