---
id: CVE-2026-15797
title: >-
  The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the
  Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored
  Cross-Site Scripting via post_title in all versions up to, and including,
  1.24.0 due to insuf…
summary: >-
  The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the
  Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored
  Cross-Site Scripting via post_title in all versions up to, and including,
  1.24.0 due to insuf…
severity: medium
cvss: 6.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: danieliser
product: >-
  Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate
  WP Popup Builder
affected:
  - >-
    popup_maker_boost_sales_conversions_optins_subscribers_with_the_ultimate_wp_popup_builder
    <= 1.24.0
published: '2026-09-18'
updated: '2026-09-19'
sourceUpdated: '2026-09-19T15:16:58.477'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15797'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/Admin/Ajax.php#L152
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/Admin/Ajax.php#L163
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/Helpers.php#L192
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/dist/assets/admin-general.js#L1
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.23.0/classes/Admin/Ajax.php#L152
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.23.0/classes/Admin/Ajax.php#L163
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.23.0/classes/Helpers.php#L192
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.23.0/dist/assets/admin-general.js#L1
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3690634/popup-maker/trunk/classes/Admin/Ajax.php
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&new=3690634%40popup-maker%2Ftags%2F1.25.0&old=3648112%40popup-maker%2Ftags%2F1.24.0
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/973b23c6-4edd-4f89-b5cf-68e83cfdb8ac?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
epss: 0.00259
epssPercentile: 0.15608
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-19T13:22:06.905574Z'
ingestedAt: '2026-09-18T09:38:46.160Z'
---

## Overview

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post_title in all versions up to, and including, 1.24.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This requires the attacker to create a post with an HTML entity-encoded payload in the title, which bypasses sanitize_text_field on save and is later decoded and executed by the browser when rendered by the Select2 component.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
