CVE-2025-24746: WordPress Popup Maker plugin <= 1.20.2 - Cross Site Scripting (XSS) vulnerability
Published Jan 24, 2025
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Iser Popup Maker popup-maker allows Stored XSS.This issue affects Popup Maker: from n/a through <= 1.20.2.
Affected Software
3 affected components
Popup Maker Popup Maker<=1.20.2
WordPress Popup Maker<=1.20.2
Code-atlantic Popup Maker Wordpress<=1.20.2
Remediation
Information
Update the WordPress Popup Maker wordpress plugin to the latest available version (at least 1.20.3).
Event History
Jan 24, 2025
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-24746?
CVE-2025-24746 is classified as a Stored Cross-site Scripting (XSS) vulnerability.
2
How do I fix CVE-2025-24746?
To fix CVE-2025-24746, update the Popup Maker plugin to a version greater than 1.20.2.
3
What software is affected by CVE-2025-24746?
CVE-2025-24746 affects Popup Maker versions up to and including 1.20.2.
4
What are the risks of CVE-2025-24746?
The risks of CVE-2025-24746 include potential data theft and unauthorized actions through malicious scripts.
5
Is CVE-2025-24746 exploitable by users?
Yes, CVE-2025-24746 can be exploited by attackers to execute scripts if they can input data into the affected system.