Junglewise Threat Intelligence

CVE-2026-15797: Popup Maker stored cross-site scripting in post title

CVE-2026-15797 · Severity: medium · CVSS 6.4 · Published 2026-09-18

Executive brief

Popup Maker is a WordPress plugin used to create pop-ups for sales conversion and lead generation. The plugin fails to properly sanitize post titles, allowing authenticated contributors to inject malicious scripts that execute in the browsers of all users viewing affected pages. An attacker could steal user data, redirect visitors, or deface content.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the post_title field of the Popup Maker WordPress plugin (versions up to 1.24.0). The root cause is insufficient input sanitization and output escaping; attackers can bypass sanitize_text_field by HTML entity-encoding payloads, which are then decoded and executed by the Select2 component when pages are rendered. The attack requires authenticated access with contributor-level privileges or above. An attacker can inject arbitrary JavaScript that persists in the database and executes whenever any user accesses an injected page. A patch should be available in versions after 1.24.0.

Affected products

  • Popup Maker Popup Maker up to and including 1.24.0

Timeline

  • 2026-09-18: disclosed

References

Related threats