CVE-2025-53995: WordPress JetPopup plugin <= 2.0.15.1 - Cross Site Scripting (XSS) Vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup allows Stored XSS. This issue affects JetPopup: from n/a through 2.0.15.1.
Other sources
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup jet-popup allows Stored XSS.This issue affects JetPopup: from n/a through <= 2.0.15.1.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-53995?
CVE-2025-53995 is classified as a high severity vulnerability due to potential stored cross-site scripting (XSS) attacks.
How do I fix CVE-2025-53995?
To fix CVE-2025-53995, update the Crocoblock JetPopup plugin to version 2.0.15.2 or later.
What products are affected by CVE-2025-53995?
CVE-2025-53995 affects the Crocoblock JetPopup and WordPress JetPopup versions up to and including 2.0.15.1.
What is the potential impact of CVE-2025-53995?
The potential impact of CVE-2025-53995 includes unauthorized script execution that can compromise the security of web applications and user data.
Who should be concerned about CVE-2025-53995?
Website administrators using affected versions of Crocoblock JetPopup or WordPress JetPopup should be concerned about CVE-2025-53995.