← WordPress Vulnerabilities
WordPress security by component

Popup box

Popup box is a WordPress component with 9 published CVE records in this archive. The latest tracked vulnerability was published Jun 26, 2026; the highest CVE/CNA score is 7.6.

Plugin slug: ays-popup-box

CVE-2026-57631: Popup box: SQL injection

Popup box is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 6.0.1.

PublishedJun 26, 2026
Known safe version6.0.2
Safe version
Jun 26, 2026 CVE-2026-57631
Popup box: SQL injection
Popup box is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data. The published affected range is n/a through 6.0.1.
6.0.2
CVE7.6
NVDPending
Jun 17, 2026 CVE-2026-54192
Popup box: Cross-site scripting
Popup box is affected by cross-site scripting. The vulnerable path is reachable without authentication. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 6.2.9.
6.3.0
CVE7.1
NVDPending
Jan 31, 2026 CVE-2026-1165
Popup Box: Cross-site request forgery
Popup Box is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Dec 30, 2025 CVE-2025-69021
Popup box: Cross-site request forgery
Popup box is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.4
NVDPending
Oct 29, 2025 CVE-2025-57931
Popup box: Cross-site request forgery
Popup box is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE5.3
NVDPending
Nov 16, 2024 CVE-2024-10861
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups: A security weakness
Popup Box – Create Countdown, Coupon, Video, Contact Form Popups is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE5.3
NVDPending
Nov 01, 2024 CVE-2024-37096
Popup box: A security weakness
Popup box is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending
May 06, 2024 CVE-2024-34367
Popup box: Cross-site scripting
Popup box is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVDPending
Jun 21, 2023 CVE-2023-27414
Ays Popup Box: Cross-site scripting
Ays Popup Box is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed.
See mitigation notes
CVE7.1
NVD6.1