CVE Database /
CVE-2025-69021
CVE · Medium
CVE-2025-69021 — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.8
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-69021
|
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.8 |
Cross-Site Request Forgery (CSRF) |
Medium
5.4
|
< 6.0.8
|
6.0.8 |
2025-12-28 |
—
|
CVE-2025-69021
The Popup Box plugin for WordPress contains a vulnerability in versions up to 6.0.7 that allows malicious individuals to deceive administrators into executing unauthorized actions by exploiting a flaw in the plugin's validation process, specifically affecting how nonces are handled. This weakness can be leveraged without requiring any prior authentication on the part of the attacker. The issue stems from an oversight in the implementation of nonce checks within the plugin's functionality.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings