<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:popup_maker:popup_maker:*:*:*:*:*:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3apopup_makerpopup_makerwordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 18 Sep 2026 12:05:29 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3apopup_makerpopup_makerwordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Popup Maker WordPress Plugin (CVE-2026-87915)</title><link>https://feed.craftedsignal.io/briefs/2026-09-wp-popup-maker-xss/</link><pubDate>Fri, 18 Sep 2026 12:05:29 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wp-popup-maker-xss/</guid><description>The Popup Maker WordPress plugin is vulnerable to Stored Cross-Site Scripting via the 'values[Name]' parameter, allowing unauthenticated attackers to inject malicious scripts that execute in the wp-admin dashboard.</description><content:encoded><![CDATA[<p>The Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress contains a Stored Cross-Site Scripting (XSS) vulnerability, tracked as CVE-2026-87915, affecting all versions up to and including 1.24.0. The vulnerability exists due to inadequate input sanitization and output escaping of the 'values[Name]' parameter.</p>
<p>Attackers can exploit this flaw by submitting crafted payloads that bypass standard WordPress sanitization functions. Specifically, HTML entities within allowed attribute values are not correctly normalized. These malicious strings are subsequently processed by the jQuery(link.attr('href')) sink in the 'wp-admin/js/common.js' script when an administrator or privileged user interacts with a contextual help tab anchor within the WordPress dashboard. This leads to the execution of arbitrary JavaScript in the victim's browser session, potentially resulting in session hijacking, administrative action spoofing, or further site compromise.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability poses a significant risk to WordPress site administrators. If exploited, an unauthenticated attacker can execute arbitrary scripts within the context of a privileged user's session. This could lead to full administrative account takeover, unauthorized modification of site content, or the installation of malicious backdoors on the affected WordPress instance. The attack is particularly concerning as it triggers via common administrative interface interactions, increasing the likelihood of successful exploitation against site owners.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the immediate update of the Popup Maker plugin to the latest version. Monitor web server access logs for anomalous POST requests directed at plugin configuration endpoints that include unusual attribute values or encoded characters.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>