PatchSiren cyber security CVE debrief
CVE-2026-28177 Daniel Iser CVE debrief
The CVE-2026-28177 record describes an Unauthenticated Cross Site Scripting (XSS) vulnerability in Popup Maker plugin versions <= 1.23.0. The affected product or component is the Popup Maker plugin. The vulnerability class is Unauthenticated Cross Site Scripting (XSS). The likely operational impact is high. Source-confidence limits are limited due to lack of detailed information. The review context is also limited. Defenders should verify affected versions and review the official CVE record for more information.
- Vendor
- Daniel Iser
- Product
- Popup Maker
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-06
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-06
Who should care
Users of Popup Maker plugin version <= 1.23.0, administrators of affected systems, and security teams monitoring for XSS vulnerabilities. They should review the official advisory and verify the plugin version to ensure it is updated or patched accordingly. Additionally, security teams should monitor for suspicious activity on affected systems and review compensating controls for exposed systems while remediation is scheduled and verified. Affected operators and platforms should also review the vulnerability management process and ensure that the necessary updates are applied. Security teams should also check relevant monitoring, detection, and logs for exposed assets that need extra review. This includes reviewing the affected product context and defensive impact to ensure that the necessary measures are taken to prevent exploitation. The vulnerability management process should also be reviewed to ensure that similar vulnerabilities are addressed in the future. Security teams should also consider asset inventory and rollback/change windows as part of their remediation strategy. Finally, they should track the source of the vulnerability and review the official CVE record for more information. This will help them to better understand the vulnerability and take the necessary steps to prevent exploitation. The affected product or component is the Popup Maker plugin, and the vulnerability class is Unauthenticated Cross Site Scripting (XSS). The likely operational impact is high, and the source-confidence limits are limited due to the lack of detailed information. The review context is also limited, and defenders should verify the affected versions and review the official CVE record for more information. The defensive priority is to patch and verify the Popup Maker plugin version, and to monitor for suspicious activity on affected systems. The recommended actions include patching the Popup Maker plugin to version above 1.23.0, verifying plugin version and updating if necessary, and monitoring for suspicious activity on affected systems. Additional recommended actions include reviewing compensating controls for exposed systems while remediation is scheduled andverified
Technical summary
The Unauthenticated Cross Site Scripting (XSS) vulnerability in Popup Maker plugin versions <= 1.23.0 has a CVSS score of 7.1 and is classified as HIGH severity. The vulnerability affects the Popup Maker plugin. Users should verify plugin versions and update if necessary. Security teams should monitor for suspicious activity on affected systems.
Defensive priority
Patch and verify Popup Maker plugin version
Recommended defensive actions
- Patch Popup Maker plugin to version above 1.23.0
- Verify plugin version and update if necessary
- Monitor for suspicious activity on affected systems
Evidence notes
Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions. Limited details available; verify with vendor and official records. The vulnerability has a CVSS score of 7.1 and is classified as HIGH severity. Users should verify the affected versions and review the official CVE record for more information.
Official resources
-
CVE-2026-28177 CVE record
CVE.org
-
CVE-2026-28177 NVD detail
NVD
-
Source item URL
nvd_modified
- Mitigation or vendor reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T15:16:53.527Z and has not been modified since then.