PatchSiren

Ays Pro CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Ays Pro CVE published 2026-06-17

CVE-2026-54192

CVE-2026-54192 is a high-severity Unauthenticated Cross Site Scripting (XSS) vulnerability in Popup box plugin versions <= 6.2.9. The vulnerability has a CVSS score of 7.1 and was published on 2026-06-17. The vulnerability allows an unauthenticated attacker to perform XSS attacks. Users of the affected plugin should take immediate action to mitigate the risk. The CVE record and NVD detail provide further [truncated]