Popup-Builder Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with Popup-Builder products.
Products
- Popup Builder1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-25744MEDIUM | WordPress Popup Builder 3.49 Persistent Cross-Site ScriptingWordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title field that execute when pages or posts display popup selections. CWE-79Jun 4, 2026 | CVSS5.1v4.0 | EPSS0.171% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |