Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 10 Apr 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Thu, 09 Apr 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ays-pro
Ays-pro popup Box |
|
| Weaknesses | CWE-918 | |
| CPEs | cpe:2.3:a:ays-pro:popup_box:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Ays-pro
Ays-pro popup Box |
Wed, 08 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 |
Tue, 07 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 07 Apr 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Popup Box
Popup Box popup Box Wordpress Wordpress wordpress |
|
| Vendors & Products |
Popup Box
Popup Box popup Box Wordpress Wordpress wordpress |
Tue, 07 Apr 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend. | |
| Title | Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-04-07T16:25:37.703Z
Reserved: 2026-03-16T18:36:17.868Z
Link: CVE-2025-15611
Updated: 2026-04-07T16:25:29.560Z
Status : Analyzed
Published: 2026-04-07T07:16:23.443
Modified: 2026-04-09T19:43:40.437
Link: CVE-2025-15611
No data.
OpenCVE Enrichment
Updated: 2026-04-13T14:27:16Z