The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Popup Box
Popup Box popup Box Wordpress Wordpress wordpress |
|
| Vendors & Products |
Popup Box
Popup Box popup Box Wordpress Wordpress wordpress |
Tue, 07 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend. | |
| Title | Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-04-07T16:25:37.703Z
Reserved: 2026-03-16T18:36:17.868Z
Link: CVE-2025-15611
No data.
Status : Awaiting Analysis
Published: 2026-04-07T07:16:23.443
Modified: 2026-04-07T13:20:11.643
Link: CVE-2025-15611
No data.
OpenCVE Enrichment
Updated: 2026-04-07T09:36:22Z
Weaknesses
No weakness.