{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3apopup_makerpopup_makerwordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:popup_maker:popup_maker:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-87915"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Popup Maker (\u003c= 1.24.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-87915, affecting all versions up to and including 1.24.0. The vulnerability exists due to inadequate input sanitization and output escaping of the 'values[Name]' parameter.\u003c/p\u003e\n\u003cp\u003eAttackers can exploit this flaw by submitting crafted payloads that bypass standard WordPress sanitization functions. Specifically, HTML entities within allowed attribute values are not correctly normalized. These malicious strings are subsequently processed by the jQuery(link.attr('href')) sink in the 'wp-admin/js/common.js' script when an administrator or privileged user interacts with a contextual help tab anchor within the WordPress dashboard. This leads to the execution of arbitrary JavaScript in the victim's browser session, potentially resulting in session hijacking, administrative action spoofing, or further site compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a significant risk to WordPress site administrators. If exploited, an unauthenticated attacker can execute arbitrary scripts within the context of a privileged user's session. This could lead to full administrative account takeover, unauthorized modification of site content, or the installation of malicious backdoors on the affected WordPress instance. The attack is particularly concerning as it triggers via common administrative interface interactions, increasing the likelihood of successful exploitation against site owners.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the immediate update of the Popup Maker plugin to the latest version. Monitor web server access logs for anomalous POST requests directed at plugin configuration endpoints that include unusual attribute values or encoded characters.\u003c/p\u003e\n","date_modified":"2026-09-18T12:05:29Z","date_published":"2026-09-18T12:05:29Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-popup-maker-xss/","summary":"The Popup Maker WordPress plugin is vulnerable to Stored Cross-Site Scripting via the 'values[Name]' parameter, allowing unauthenticated attackers to inject malicious scripts that execute in the wp-admin dashboard.","title":"Stored XSS in Popup Maker WordPress Plugin (CVE-2026-87915)","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-popup-maker-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:popup_maker:popup_maker:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}