• PoC PUBLIC

CVE-2026-87915: stored cross-site scripting in danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder

Unauthenticated attackers can inject persistent JavaScript into sites using the Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin and cause that script to run when a page with the injected content is viewed. This is tracked as CVE-2026-87915. Versions 1.24.0 and earlier of the 1.x branch are affected; the issue stems from insufficient sanitization and escaping of the values[Name] parameter, and an attacker only needs network access to submit crafted input that will be stored and later executed in a victim’s browser.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00494
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists, so prioritize mitigation now; treat sites with this plugin as high risk until a vendor fix is available.

What is CVE-2026-87915?

Unauthenticated attackers can inject persistent JavaScript into sites using the Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin and cause that script to run when a page with the injected content is viewed. This is tracked as CVE-2026-87915. Versions 1.24.0 and earlier of the 1.x branch are affected; the issue stems from insufficient sanitization and escaping of the values[Name] parameter, and an attacker only needs network access to submit crafted input that will be stored and later executed in a victim’s browser. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder are affected?

BRANCHAFFECTEDFIXED
1.x1.24.0 and earlier

Is CVE-2026-87915 being exploited?

Public exploit code is available.

How to fix CVE-2026-87915

  1. Remove or deactivate the vulnerable Popup Maker plugin until a vendor patch is released.
  2. Restrict access to WordPress administrative and content-editing capabilities to trusted accounts only.
  3. Deploy a web application firewall rule to block suspicious inputs targeting values[Name] and to filter XSS payloads.
  4. Monitor web and application logs for indicators of stored XSS and review recent changes to popup content and contextual help tabs.

Frequently asked questions

Is CVE-2026-87915 being actively exploited?

Public exploit code for CVE-2026-87915 is available, indicating the vulnerability can be exploited; no additional exploitation attribution is provided in the facts.

Which Popup Maker versions are affected by CVE-2026-87915?

Popup Maker versions 1.24.0 and earlier in the 1.x branch are listed as affected.

Is there a patch for CVE-2026-87915?

No vendor patch is listed in the provided facts; a fixed version is not specified.

Does CVE-2026-87915 require authentication?

No authentication is required for this vulnerability according to the available information; attackers can submit the malicious input without signing in.

References