CVE Database /
CVE-2019-25744
CVE · Medium
CVE-2019-25744 — Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] <= 3.49 (unfixed)
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-25744
|
Popup Builder – Create highly converting, mobile friendly marketing popups. [popup-builder] <= 3.49 (unfixed) |
— |
Medium
5.4
|
< 3.49
|
3.49 |
2026-06-04 |
—
|
CVE-2019-25744
The Popup Builder plugin through version 3.49 has a persistent cross-site scripting flaw that permits authenticated users to inject arbitrary scripts by escaping option tag constraints in the post_title parameter. An attacker could craft malicious POST requests targeting the post.php endpoint with script code embedded in the post_title field, which would then execute when the popup selection appears on pages or posts. This vulnerability has not been fixed in any subsequent release.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings