CVE-2025-53994: WordPress JetPopup plugin <= 2.0.15 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup allows DOM-Based XSS. This issue affects JetPopup: from n/a through 2.0.15.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup jet-popup allows DOM-Based XSS.This issue affects JetPopup: from n/a through <= 2.0.15.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53994?
CVE-2025-53994 is classified as a medium severity vulnerability due to the risk of cross-site scripting (XSS) attacks.
How do I fix CVE-2025-53994?
To mitigate CVE-2025-53994, update the Crocoblock JetPopup plugin to the latest version that addresses the XSS issue.
What types of attacks can CVE-2025-53994 enable?
CVE-2025-53994 can enable attackers to execute arbitrary JavaScript in the context of a victim's browser, potentially leading to data theft or session hijacking.
Which versions of JetPopup are affected by CVE-2025-53994?
CVE-2025-53994 affects JetPopup versions from n/a through 2.0.15.
Who is impacted by CVE-2025-53994?
Users of Crocoblock JetPopup and WordPress JetPopup plugins versions up to 2.0.15 are impacted by CVE-2025-53994.