PT-2026-46214 · Popup Builder · Popup Builder

Unk9Vvn

·

Published

2026-06-04

·

Updated

2026-06-04

·

CVE-2019-25744

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post title field that execute when pages or posts display popup selections.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-25744

Affected Products

Popup Builder