DIRAS TAKE
Urgent: public exploit code exists, so prioritize mitigation now; treat sites with this plugin as high risk until a vendor fix is available.
What is CVE-2026-87915?
Unauthenticated attackers can inject persistent JavaScript into sites using the Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin and cause that script to run when a page with the injected content is viewed. This is tracked as CVE-2026-87915. Versions 1.24.0 and earlier of the 1.x branch are affected; the issue stems from insufficient sanitization and escaping of the values[Name] parameter, and an attacker only needs network access to submit crafted input that will be stored and later executed in a victim’s browser. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.24.0 and earlier |
Is CVE-2026-87915 being exploited?
Public exploit code is available.
How to fix CVE-2026-87915
- Remove or deactivate the vulnerable Popup Maker plugin until a vendor patch is released.
- Restrict access to WordPress administrative and content-editing capabilities to trusted accounts only.
- Deploy a web application firewall rule to block suspicious inputs targeting values[Name] and to filter XSS payloads.
- Monitor web and application logs for indicators of stored XSS and review recent changes to popup content and contextual help tabs.
Frequently asked questions
Is CVE-2026-87915 being actively exploited?
Public exploit code for CVE-2026-87915 is available, indicating the vulnerability can be exploited; no additional exploitation attribution is provided in the facts.
Which Popup Maker versions are affected by CVE-2026-87915?
Popup Maker versions 1.24.0 and earlier in the 1.x branch are listed as affected.
Is there a patch for CVE-2026-87915?
No vendor patch is listed in the provided facts; a fixed version is not specified.
Does CVE-2026-87915 require authentication?
No authentication is required for this vulnerability according to the available information; attackers can submit the malicious input without signing in.
References
- nvd.nist.gov/vuln/detail/CVE-2026-87915
- cve.org/CVERecord?id=CVE-2026-87915
- wordfence.com/threat-intel/vulnerabilities/id/ea8b1eee-2e3f-4d61-b815-4ea0aaa188b5?source=cve
- plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Admin/Subscribers/Table.php#L281
- plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/ListTable.php#L1408
- plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Newsletters.php#L74
- plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Newsletters.php#L273
- plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Abstract/Database.php#L359
- plugins.trac.wordpress.org/browser/popup-maker/tags/1.24.0/classes/Newsletters.php#L59
- plugins.trac.wordpress.org/changeset?reponame=&new=3690634%40popup-maker%2Ftags%2F1.25.0&old=3648112%40popup-maker%2Ftags%2F1.24.0
- plugins.trac.wordpress.org/changeset/3690634/popup-maker/trunk/classes/Admin/Subscribers/Table.php
- All danieliser CVEs on CVE Radar
- CVEs published in September 2026