CVE-2025-15611 PUBLISHED

Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF

Assigner: WPScan
Reserved: 16.03.2026 Published: 07.04.2026 Updated: 07.04.2026

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend.

Product Status

Vendor Unknown
Product Popup Box
Versions Default: unaffected
  • affected from 0 to 5.5.0 (excl.)

Credits

  • Spider Sec Ltd finder
  • WPScan coordinator

References

Problem Types

  • CWE-79 Cross-Site Scripting (XSS) CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE