Plugin Vulnerability Hub
Plugin 18 known issues Latest disclosed Apr 08, 2026

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Vulnerabilities

Review known vulnerability records for the WordPress plugin Popup Box – Create Countdown, Coupon, Video, Contact Form Popups (`ays-popup-box`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2025-15611, CVE-2026-1165 and CVE-2025-69021, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
18
High or Critical
2
Patch Coverage
100%
Last Updated
Apr 13, 2026
Priority CVE Quick Links

Fast paths into Popup Box – Create Countdown, Coupon, Video, Contact Form Popups CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
16
CVE-2021-24458 High 2.3.4
CVE-2021-24458 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups SQL Injection

Popup box < 2.3.4 - Authenticated SQL Injection

CVE-2025-15611 High 5.5.0
CVE-2025-15611 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Stored Cross-Site Scripting

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups < 5.5.0 - Unauthenticated Stored Cross-Site Scripting

CVE-2023-6591 Medium 20.9.0
CVE-2023-6591 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Stored Cross-Site Scripting

Popup Box Business (7.0.0 - 7.9.0) and Developer (20.0.0 - 20.9.0) - Authenticated (Admin+) Stored Cross-Site Scripting

CVE-2024-34367 Medium 4.1.3
CVE-2024-34367 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Cross-Site Request Forgery

Popup box <= 4.1.2 - Cross-Site Request Forgery

CVE-2023-27414 Medium 3.4.5
CVE-2023-27414 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Cross-Site Scripting

Popup box <= 3.4.4 - Reflected Cross-Site Scripting via 'ays_pb_tab' Parameter

CVE-2024-10861 Medium 4.9.8
CVE-2024-10861 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Vulnerability

Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update

CVE-2024-3897 Medium 4.3.7
CVE-2024-3897 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Vulnerability

Popup Box – Best WordPress Popup Plugin <= 4.3.6 - Missing Authorization to Information Exposure

CVE-2024-9599 Medium 4.7.8
CVE-2024-9599 Popup Box – Create Countdown, Coupon, Video, Contact Form Popups Stored Cross-Site Scripting

Popup Box <= 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for Popup Box – Create Countdown, Coupon, Video, Contact Form Popups so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
18 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
0 critical and 2 high severity findings.
Recent CVEs
CVE-2025-15611, CVE-2026-1165 and CVE-2025-69021
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Popup Box – Create Countdown, Coupon, Video, Contact Form Popups

Sorted by latest disclosure date so newly published issues surface first.

Plugin High Patched: Yes CVE-2025-15611
CVE-2025-15611: Popup Box – Create Countdown, Coupon, Video, Contact Form Popups < 5.5.0 - Unauthenticated Stored Cross-Site Scripting

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to 5.5.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to injec...

Published
Apr 08, 2026
Patched Release
5.5.0
Affected Versions
Versions before 5.5.0
Next Step
Update to 5.5.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1165
CVE-2026-1165: Popup Box <= 6.1.1 - Cross-Site Request Forgery to Popup Status Change

The Popup Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.1.1. This is due to a flawed nonce implementation in the 'publish_unpublish_popupbox' function that verifies a self-created nonce rather than one submitted in th...

Published
Jan 30, 2026
Patched Release
6.1.2
Affected Versions
Versions up to 6.1.1
Next Step
Update to 6.1.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-69021
CVE-2025-69021: Popup box <= 6.0.7 - Cross-Site Request Forgery

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.0.7. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauth...

Published
Dec 28, 2025
Patched Release
6.0.8
Affected Versions
Versions up to 6.0.7
Next Step
Update to 6.0.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-57931
CVE-2025-57931: Popup box <= 5.5.4 - Cross-Site Request Forgery

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.5.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauth...

Published
Oct 29, 2025
Patched Release
5.5.5
Affected Versions
Versions up to 5.5.4
Next Step
Update to 5.5.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-10861
CVE-2024-10861: Popup Box – Create Countdown, Coupon, Video, Contact Form Popups <= 4.9.7 - Missing Authorization to Unauthenticated Limited Options Update

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including, 4.9.7. This makes it pos...

Published
Nov 15, 2024
Patched Release
4.9.8
Affected Versions
Versions up to 4.9.7
Next Step
Update to 4.9.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-9599
CVE-2024-9599: Popup Box <= 4.7.7 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.7.7 due to insufficient input sanitization and output escaping. This makes it possible...

Published
Oct 31, 2024
Patched Release
4.7.8
Affected Versions
Versions up to 4.7.7
Next Step
Update to 4.7.8 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-37096
CVE-2024-37096: Popup box <= 4.5.1 - Missing Authorization

The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.5.1. This makes it possible for authenticated attackers, with sub...

Published
Jun 20, 2024
Patched Release
4.5.2
Affected Versions
Versions up to 4.5.1
Next Step
Update to 4.5.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-34367
CVE-2024-34367: Popup box <= 4.1.2 - Cross-Site Request Forgery

The Popup box plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.1.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious web scripts via a f...

Published
May 03, 2024
Patched Release
4.1.3
Affected Versions
Versions up to 4.1.2
Next Step
Update to 4.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-3897
CVE-2024-3897: Popup Box – Best WordPress Popup Plugin <= 4.3.6 - Missing Authorization to Information Exposure

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the ays_pb_create_author AJAX action in all versions up to, and including, 4.3.6. This makes it possible for unauthenticated attacker...

Published
Apr 24, 2024
Patched Release
4.3.7
Affected Versions
Versions up to 4.3.6
Next Step
Update to 4.3.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-6591
CVE-2023-6591: Popup Box Business (7.0.0 - 7.9.0) and Developer (20.0.0 - 20.9.0) - Authenticated (Admin+) Stored Cross-Site Scripting

The Popup Box Business and Developer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions 20.0.0 to 20.9.0 (Developer) and versions 7.0.0 to 7.9.0 (Business) due to insufficient input sanitization and output escaping. This makes it poss...

Published
Jan 22, 2024
Patched Release
20.9.0
Affected Versions
20.0.0 up to before 20.9.0
Next Step
Update to 20.9.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-5809
CVE-2023-5809: Popup Box <= 3.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 3.8.7 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Published
Nov 13, 2023
Patched Release
3.8.7
Affected Versions
Versions before 3.8.7
Next Step
Update to 3.8.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-5874
CVE-2023-5874: Popup Box <= 3.8.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Popup Box – Best WordPress Popup Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to 3.8.7 (exclusive) due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,...

Published
Nov 13, 2023
Patched Release
3.8.7
Affected Versions
Versions before 3.8.7
Next Step
Update to 3.8.7 or newer if supported.