CVE-2025-39397: WordPress Anything Popup plugin <= 7.3 - Reflected Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Anything Popup allows Reflected XSS. This issue affects Anything Popup: from n/a through 7.3.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Anything Popup anything-popup allows Reflected XSS.This issue affects Anything Popup: from n/a through <= 7.3.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39397?
CVE-2025-39397 is classified as a reflected Cross Site Scripting (XSS) vulnerability which can potentially allow an attacker to execute malicious scripts in a user's browser.
How do I fix CVE-2025-39397?
To fix CVE-2025-39397, update the Anything Popup plugin to version 7.4 or later, which contains security patches for this vulnerability.
What versions of Anything Popup are affected by CVE-2025-39397?
CVE-2025-39397 affects all versions of the Anything Popup plugin up to and including version 7.3.
What can an attacker achieve with CVE-2025-39397?
An attacker exploiting CVE-2025-39397 can execute arbitrary JavaScript in the context of the user’s session, potentially leading to data theft or account compromise.
Is CVE-2025-39397 a widespread issue?
Yes, CVE-2025-39397 is a concern for any websites using the vulnerable versions of the Anything Popup plugin, potentially affecting many WordPress installations.