Junglewise Threat Intelligence

CVE-2026-88853: Regular Labs Modals Pro stored XSS via event handler

CVE-2026-88853 · Severity: info · CVSS 6.3 · Published 2026-09-14

Vendors: Regular Labs.

Executive brief

Modals Pro is a Joomla extension that enables administrators to create modal popup windows on websites. A privilege-escalation vulnerability allows lower-privileged authors to inject malicious JavaScript code through event handler options that should only be available to trusted administrators, enabling them to execute arbitrary scripts when users interact with modals.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in Modals Pro for Joomla. The extension intentionally supports JavaScript event handlers (such as on-open and on-closed) for modal popups, but fails to restrict their use to trusted administrators. Lower-privileged content authors can inject malicious JavaScript through article content and event handler fields, which is then stored and executed in the browsers of site visitors. The root cause is insufficient privilege checking: the extension does not distinguish between trusted extension configuration and user-supplied event code. An authenticated author with normal article-posting permissions can exploit this without requiring additional user interaction. The impact allows arbitrary JavaScript execution in the context of the website, potentially leading to session hijacking, credential theft, or further compromise. Versions below 17.0.0 are affected.

Affected products

  • Regular Labs Modals Pro < 17.0.0

Timeline

  • 2026-09-14: disclosed: CVE-2026-88853 published
  • 2026-09-14: advisory: NVD advisory released

References

Related threats