CVE · Medium

CVE-2025-69021 — Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.8

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-69021 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.8 Cross-Site Request Forgery (CSRF) Medium 5.4 < 6.0.8 6.0.8 2025-12-28

CVE-2025-69021

The Popup Box plugin for WordPress contains a vulnerability in versions up to 6.0.7 that allows malicious individuals to deceive administrators into executing unauthorized actions by exploiting a flaw in the plugin's validation process, specifically affecting how nonces are handled. This weakness can be leveraged without requiring any prior authentication on the part of the attacker. The issue stems from an oversight in the implementation of nonce checks within the plugin's functionality.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.