WP Clinic
Log in Sign up

CVE

CVE-2025-15611 — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 5.5.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-15611 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 5.5.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 5.5.0 5.5.0 2026-04-07

CVE-2025-15611

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend.

Source: CVE.org

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.