PT-2026-26263 · WordPress · Wordpress Instant Popup Builder
Youcef Hamdani
·
Published
2026-03-19
·
Updated
2026-03-23
·
CVE-2026-3475
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress Instant Popup Builder versions up to and including 1.1.7
Description
The Instant Popup Builder plugin for WordPress is susceptible to Unauthenticated Arbitrary Shortcode Execution. This occurs because the
handle email verification page() function creates a shortcode string from user-provided token and email GET parameters and passes it to do shortcode() without sufficient sanitization of square bracket characters, and lacks authorization checks. The sanitize text field() and esc attr() functions do not remove or escape square bracket characters. A malicious token value containing a ']' character can prematurely close a shortcode tag, allowing unauthenticated attackers to inject and execute arbitrary registered shortcodes.Recommendations
Update WordPress Instant Popup Builder to a version later than 1.1.7.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wordpress Instant Popup Builder