CVE-2025-69026: WordPress PopupKit plugin <= 2.2.4 - Sensitive Data Exposure vulnerability
Published Dec 30, 2025
·Updated
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Roxnor PopupKit popup-builder-block allows Retrieve Embedded Sensitive Data.This issue affects PopupKit: from n/a through <= 2.2.4.
Affected Software
2 affected components
Roxnor PopupKit popup-builder-block<=2.1.5
Roxnor PopupKit<=2.2.4
Event History
Dec 30, 2025
CVE Published
via MITRE·10:47 AM
Data Sourced
via MITRE·10:47 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-69026?
CVE-2025-69026 is classified as a medium severity vulnerability due to the exposure of sensitive system information.
2
How do I fix CVE-2025-69026?
To fix CVE-2025-69026, update PopupKit to version 2.1.6 or later.
3
What software is affected by CVE-2025-69026?
CVE-2025-69026 affects PopupKit versions up to and including 2.1.5 on both npm and WordPress platforms.
4
What type of data is exposed in CVE-2025-69026?
CVE-2025-69026 allows the retrieval of embedded sensitive data from the system.
5
Who is impacted by CVE-2025-69026?
Users of PopupKit plugin versions up to 2.1.5 are at risk from the CVE-2025-69026 vulnerability.