Medium severity5.4NVD Advisory· Published Apr 7, 2026· Updated Apr 9, 2026
CVE-2025-15611
CVE-2025-15611
Description
The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- wpscan.com/vulnerability/089ea763-2421-4089-a220-251421f7f226/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.