Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Popup box — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in Popup box, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for the specific software component known as the Popup box. The collection encompasses reported security flaws associated with this component, covering the full historical range of documented advisories. Readers can use this resource to track the vendor's published security notices, analyze the underlying weakness class, and review the complete vulnerability history for this product.

Vendor: Ays Pro

CVE ID Title CVSS Severity Published
CVE-2026-57631 WordPress Popup box plugin <= 6.0.1 - SQL Injection vulnerability CWE-89 7.6 High 2026-06-26
CVE-2026-54192 WordPress Popup box plugin <= 6.2.9 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High 2026-06-17
CVE-2025-15611 Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF 7.1AI High AI 2026-04-07
CVE-2025-69021 WordPress Popup box plugin <= 6.0.7 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium 2025-12-30
CVE-2025-57931 WordPress Popup box plugin <= 5.5.4 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.3 Medium 2025-10-29
CVE-2024-9599 Popup Box < 4.7.8 - Admin+ Stored XSS 4.8AI Medium AI 2025-05-15
CVE-2025-24711 WordPress Popup Box Plugin <= 3.2.4 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium 2025-01-24
CVE-2024-37096 WordPress Popup box plugin <= 4.5.1 - Broken Access Control vulnerability CWE-862 4.3 Medium 2024-11-01
CVE-2024-34367 WordPress Popup Box plugin <= 4.1.2 - CSRF to XSS vulnerability CWE-352 7.1 High 2024-05-06
CVE-2023-6591 Popup Box Pro < 20.9.0 - Admin+ Stored XSS 4.8 - 2024-02-12
CVE-2023-5809 Popup box < 3.8.6 - Admin+ Stored XSS in Categories 4.8AI Medium AI 2023-12-04
CVE-2023-5874 Popup box < 3.8.6 - Admin+ Stored XSS in Popup Settings 4.8AI Medium AI 2023-12-04
CVE-2023-5343 Popup Box < 3.7.9 - Admin+ Stored XSS 4.8AI Medium AI 2023-11-20
CVE-2023-4390 Popup box < 3.7.2 - Admin+ Stored Cross-Site Scripting 4.8 - 2023-10-31
CVE-2023-27414 WordPress Popup box Plugin <= 3.4.4 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High 2023-06-21
CVE-2021-24458 Popup box < 2.3.4 - Authenticated Blind SQL Injections CWE-89 8.8 - 2021-08-02

All 16 known CVE vulnerabilities affecting Popup box with full Chinese analysis, references, and POCs where available.