Executive brief
Popup Builder is a popular WordPress plugin used to create and manage marketing popups on websites. A security vulnerability in version 3.49 allows an attacker with basic account access to inject malicious scripts into the website. These scripts execute automatically when other users or administrators view certain pages, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A persistent cross-site scripting (XSS) vulnerability exists in WordPress Popup Builder 3.49 due to improper neutralization of input in the 'post_title' parameter. An authenticated attacker can submit a crafted POST request to the 'post.php' endpoint containing a script payload that breaks out of HTML <option> tags. This payload is stored in the database and executes whenever an administrator or user visits the 'Add New' page or post sections where popup selections are displayed. The vulnerability is triggered because the plugin fails to sanitize the popup title before rendering it within the selection interface of the WordPress administrative dashboard.
Affected products
- Sygnoos Popup Builder 3.49
Timeline
- 2019-06-13: disclosed: Initial discovery by researcher
- 2019-10-17: other: Exploit published on Exploit-DB
- 2026-06-04: advisory: NVD publication date