Junglewise Threat Intelligence

CVE-2026-54192: Ays Pro Popup box unauthenticated XSS

CVE-2026-54192 · Severity: high · CVSS 7.1 · Published 2026-06-17

Vendors: AYS Pro.

Executive brief

The Popup box plugin for WordPress, which allows site owners to create promotional and informational popups, is vulnerable to a security flaw that could allow attackers to run malicious scripts on your website. By tricking a site visitor or administrator into clicking a specific link, an attacker could steal login sessions, redirect users to malicious websites, or deface site content. This issue affects all versions up to 6.2.9 and can be resolved by updating to version 6.3.0.

Technical details

The Ays Pro Popup box plugin for WordPress (versions <= 6.2.9) contains a reflected Cross-Site Scripting (XSS) vulnerability due to improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by crafting a malicious URL and tricking a user into visiting it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized actions on behalf of a privileged user. The vulnerability is patched in version 6.3.0.

Affected products

  • Ays Pro Popup box <= 6.2.9

Timeline

  • 2026-05-20: other: Reported by João Pedro S Alcântara (Kinorth)
  • 2026-06-16: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date

References

Related threats