CVE-2026-11996: Advanced Popups <= 1.2.3 - Authenticated (Author+) Stored Cross-Site Scripting via 'Notification Button Link' Field
The Advanced Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'Notification Button Link' Field in all versions up to, and including, 1.2.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with author-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with the Author role or a higher-privileged role can exploit it. The attacker must be able to supply a crafted value in the Notification Button Link field.
What is the impact if exploitation succeeds?
Injected script is stored in affected content and executes when a user visits the injected page. The vulnerability can affect confidentiality and integrity, while no availability impact is indicated.
Which versions are affected, and is a fix available?
Advanced Popups versions through 1.2.3 are affected. The referenced plugin change identifies version 1.2.4 as the newer version.