AI description
CVE-2025-15611 describes a Cross-Site Request Forgery (CSRF) vulnerability found in the Popup Box WordPress plugin, affecting versions prior to 5.5.0. The flaw originates from the `add_or_edit_popupbox()` function's failure to adequately validate nonces before saving popup data. This vulnerability enables unauthenticated attackers to execute CSRF attacks. If an authenticated administrator visits a specially crafted malicious page, the attacker can exploit this to create or modify popups containing arbitrary JavaScript. This malicious JavaScript then executes within both the WordPress administration panel and the website's frontend.
- Description
- The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend.
- Source
- contact@wpscan.com
- NVD status
- Analyzed
- Products
- popup_box
CVSS 3.1
- Type
- Secondary
- Base score
- 5.4
- Impact score
- 2.7
- Exploitability score
- 2.3
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- nvd@nist.gov
- CWE-918
- Hype score
- Not currently trending
https://t.co/rR73lgIWWJ CVE-2025-15611 #WordPress plugin #vulnerability ays-popup-box #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge
@atomicedgeWAF
20 Apr 2026
111 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨*CVE* CVE-2025-15611 The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticat… https://t.co/N1cJI48q8A ----- Traducción: CVE-2025-15611 El … https://t.co/utmtNg
@infoflowcloud
19 Apr 2026
159 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15611 The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticat… https://t.co/0x1g1WI1nJ
@CVEnew
19 Apr 2026
427 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-15611 Cross-Site Request Forgery in Popup Box WordPress Plugin Before 5.5.0 https://t.co/720rKSxrPl
@VulmonFeeds
7 Apr 2026
65 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15611 - Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF Intel Report: https://t.co/50dMBz3EUN
@cyberbivash
7 Apr 2026
90 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:ays-pro:popup_box:*:*:*:*:*:wordpress:*:*",
"matchCriteriaId": "BEED5733-F8BB-4B2B-B0C1-C849505A712C",
"versionEndExcluding": "5.5.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]