CVE · Medium

CVE-2025-53994 — JetPopup [jet-popup] < 2.0.15.1

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-53994 JetPopup [jet-popup] < 2.0.15.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.5 < 2.0.15.1 2.0.15.1 2025-07-16

CVE-2025-53994

The JetPopup plugin for WordPress contains a security flaw that allows malicious users with contributor-level permissions or higher to embed unauthorized code snippets into website content. This vulnerability arises from inadequate filtering of input data and insufficient protection against potentially hazardous output. As a result, when a visitor views the compromised webpage, the injected code will be executed.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.