CVE-2025-62902: WordPress WP Popup Builder plugin <= 1.3.8 - Sensitive Data Exposure vulnerability
Published Oct 27, 2025
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in ThemeHunk WP Popup Builder wp-popup-builder allows Retrieve Embedded Sensitive Data.This issue affects WP Popup Builder: from n/a through <= 1.3.8.
Affected Software
3 affected components
ThemeHunk WP Popup Builder<=1.3.6
WordPress WP Popup Builder<=1.3.6
ThemeHunk Wp Popup Builder Wordpress<=1.3.6
Event History
Oct 27, 2025
CVE Published
via MITRE·01:33 AM
Data Sourced
via MITRE·01:33 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-62902?
The severity of CVE-2025-62902 is categorized as high due to the exposure of sensitive system information.
2
How do I fix CVE-2025-62902?
To fix CVE-2025-62902, update the WP Popup Builder plugin to the latest version beyond 1.3.6.
3
What type of information is exposed in CVE-2025-62902?
CVE-2025-62902 exposes embedded sensitive data that can be retrieved by unauthorized users.
4
Which versions of the WP Popup Builder are affected by CVE-2025-62902?
CVE-2025-62902 affects WP Popup Builder versions from n/a to 1.3.6 inclusive.
5
Who is the vendor associated with CVE-2025-62902?
The vendor associated with CVE-2025-62902 is ThemeHunk.