CVE · Medium

CVE-2019-25744 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] <= 3.49 (unfixed)

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-25744 Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] <= 3.49 (unfixed) Medium 5.4 < 3.49 3.49 2026-06-04

CVE-2019-25744

The Popup Builder plugin through version 3.49 has a persistent cross-site scripting flaw that permits authenticated users to inject arbitrary scripts by escaping option tag constraints in the post_title parameter. An attacker could craft malicious POST requests targeting the post.php endpoint with script code embedded in the post_title field, which would then execute when the popup selection appears on pages or posts. This vulnerability has not been fixed in any subsequent release.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.