Impact
Popup Maker contains inadequate input sanitization that allows an attacker to persist arbitrary JavaScript in the values[Name] field. When a user views a page that renders this field, the malicious script runs in the victim’s browser, providing client‑side code execution. This flaw is a classic example of CWE‑79 – Improper Neutralization of Input During Web Page Generation.
Affected Systems
Any WordPress site that has installed the Popup Maker plugin from vendor danieliser:Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder, in any release up to and including version 1.24.0. The compromise targets subscriber and newsletter modules where the values[Name] parameter is accepted.
Risk and Exploitability
The CVSS base score of 7.2 indicates a moderate‑to‑high impact. The EPSS score is less than 1 %, implying that exploitation is currently rare, and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw unauthenticated by injecting payloads into the values[Name] field via the subscriber or newsletter management pages; the stored payload is later executed whenever a user accesses an affected page. This can lead to session hijacking, defacement, or further client‑side attacks.
OpenCVE Enrichment