Junglewise Threat Intelligence

CVE-2026-57631: Ays Pro Popup box SQL injection in administrator interface

CVE-2026-57631 · Severity: high · CVSS 7.6 · Published 2026-06-26

Vendors: AYS Pro.

Executive brief

Ays Pro Popup box, a WordPress plugin used to create and manage promotional popups, contains a security vulnerability that could allow an administrative user to perform unauthorized database operations. If exploited, an attacker with high-level access could bypass security controls to extract sensitive information from the website's database. While the risk is mitigated by the requirement for administrator privileges, it represents a significant threat to data integrity and confidentiality if an admin account is compromised.

Technical details

The Ays Pro Popup box plugin for WordPress (versions 6.0.1 and below) is vulnerable to SQL injection due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability exists in a component accessible to users with Administrator-level privileges. An attacker with these permissions can send specially crafted network requests to execute arbitrary SQL queries against the underlying database. This could lead to the exfiltration of sensitive data or limited impact on service availability. The issue is addressed in version 6.0.2.

Affected products

  • Ays Pro Popup box <= 6.0.1

Timeline

  • 2025-11-02: other: Reported by researcher Doan Dinh Van
  • 2026-06-26: disclosed: Published by Patchstack
  • 2026-06-26: patched: Fixed in version 6.0.2

References

Related threats