PLUGIN SECURITY

Is Ays Popup Box safe?

Build flexible popups and modal windows with multiple popup types, triggers, and display controls.

What this plugin does

  • Slug: ays-popup-box
  • Author: Ays Pro
  • 50000+ active installs
  • 92/100 rating (81 reviews on wordpress.org)
  • 3762535 all-time downloads
  • On WordPress.org since 2018-06-16

exit popupmodalpop uppopuppopups

Maintenance status

  • Latest known version: 6.3.7
  • Last updated: 2026-08-26 6:08am GMT
  • Tested up to WordPress: 7.1

Known vulnerabilities

18 known CVEs on file for Ays Popup Box.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-57631 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.2 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 7.6 < 6.0.2 6.0.2 2026-06-26 ✓ fixed in latest
CVE-2026-54192 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.3.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 6.3.0 6.3.0 2026-06-16 ✓ fixed in latest
CVE-2025-15611 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 5.5.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 5.5.0 5.5.0 2026-04-07 ✓ fixed in latest
CVE-2025-69021 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.0.8 Cross-Site Request Forgery (CSRF) Medium 5.4 < 6.0.8 6.0.8 2025-12-28 ✓ fixed in latest
CVE-2024-10861 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.9.8 Missing Authorization Medium 5.3 < 4.9.8 4.9.8 2024-11-15 ✓ fixed in latest
CVE-2024-37096 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.5.2 Missing Authorization Medium 4.3 < 4.5.2 4.5.2 2024-06-20 ✓ fixed in latest
CVE-2024-34367 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.1.3 Cross-Site Request Forgery (CSRF) High 7.1 < 4.1.3 4.1.3 2024-05-03 ✓ fixed in latest
CVE-2024-3897 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.3.7 Missing Authorization Medium 5.3 < 4.3.7 4.3.7 2024-04-24 ✓ fixed in latest
+ 19 more known vulnerabilities
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-6591 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.9.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 20.9.0 20.9.0 2024-01-22 ⚠ update needed
CVE-2023-5874 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.8.7 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.8.7 3.8.7 2023-11-13 ✓ fixed in latest
CVE-2023-5809 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.8.6 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.8.6 3.8.6 2023-11-13 ✓ fixed in latest
CVE-2023-5343 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.7.9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.7.9 3.7.9 2023-10-27 ✓ fixed in latest
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.7.2 Unknown < 3.7.2 3.7.2 2023-08-31 ✓ fixed in latest
CVE-2023-4390 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.7.2 3.7.2 2023-08-29 ✓ fixed in latest
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.7.1 Unknown < 3.7.1 3.7.1 2023-08-18 ✓ fixed in latest
CVE-2023-27414 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 3.4.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.1 < 3.4.5 3.4.5 2023-03-08 ✓ fixed in latest
CVE-2021-24458 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 2.3.4 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') High 8.8 < 2.3.4 2.3.4 2021-06-29 ✓ fixed in latest
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 2.3.4 Unknown < 2.3.4 2.3.4 2021-06-29 ✓ fixed in latest
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 4.7.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 4.7.8 4.7.8 0000-00-00 ✓ fixed in latest
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 6.1.2 Medium 4.3 < 6.1.2 6.1.2 0000-00-00 ✓ fixed in latest
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups [ays-popup-box] < 2.3.4 Unknown < 2.3.4 2.3.4 ✓ fixed in latest
Multiple Plugins from AYS Pro - Reflected Cross-Site Scripting (XSS) Unknown < 2.3.4 2.3.4 ✓ fixed in latest
CVE-2023-4390 Popup box < 3.7.2 - Admin+ Stored Cross-Site Scripting Unknown < 3.7.2 3.7.2 ✓ fixed in latest
CVE-2023-5874 Popup box < 3.8.6 - Admin+ Stored XSS in Popup Settings Unknown < 3.8.6 3.8.6 ✓ fixed in latest
CVE-2024-9599 Popup Box < 4.7.8 - Admin+ Stored XSS Unknown < 4.7.8 4.7.8 ✓ fixed in latest
CVE-2025-57931 Popup box < 5.5.5 - Cross-Site Request Forgery Unknown < 5.5.5 5.5.5 ✓ fixed in latest
CVE-2026-1165 Popup Box < 6.1.2 - Cross-Site Request Forgery to Popup Status Change Unknown < 6.1.2 6.1.2 ✓ fixed in latest

How to fix it

Keep Ays Popup Box updated — 6.3.7 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.