PatchSiren

Popup-Builder CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Popup-Builder CVE published 2026-06-04

CVE-2019-25744

CVE-2019-25744 is a persistent cross-site scripting (XSS) vulnerability in WordPress Popup Builder 3.49. The vulnerability allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads in the post_title field, which execute when pages or posts display popup selections.