CVE-2026-54192
Deferred Deferred - Pending Action
BaseFortify

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack popup_box_plugin to 6.2.9 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-54192 is a Cross Site Scripting (XSS) vulnerability found in the WordPress Popup box Plugin versions 6.2.9 and below.

This vulnerability allows attackers to inject malicious scripts into websites using the plugin. When visitors access the affected site, these scripts can execute, potentially causing harmful actions such as redirects or displaying unwanted content.

Exploitation requires user interaction, like clicking a malicious link, but it can be used in mass-exploit campaigns targeting many websites.

The vulnerability has a CVSS score of 7.1, indicating a moderate risk, and was patched in version 6.3.0 of the plugin.

Impact Analysis

This vulnerability can impact you by allowing attackers to execute malicious scripts on your website if you use the affected Popup box Plugin version 6.2.9 or below.

Such scripts can perform unwanted actions like redirecting your visitors to malicious sites or displaying harmful or misleading content.

Because exploitation requires user interaction, the risk depends on your users clicking malicious links, but attackers can target many sites simultaneously.

If exploited, this can damage your website's reputation, compromise user trust, and potentially lead to further security issues.

Detection Guidance

The vulnerability is a reflected Cross Site Scripting (XSS) in the WordPress Popup box Plugin versions 6.2.9 and below. Detection typically involves monitoring for suspicious script injections or unusual URL parameters that trigger the XSS.

While no specific commands are provided in the available resources, common detection methods include using web application scanners or manual testing by sending crafted requests to the affected plugin endpoints to check for script execution.

Additionally, applying the mitigation rule provided by Patchstack can help block attacks until the plugin is updated.

Mitigation Strategies

The immediate step to mitigate this vulnerability is to update the WordPress Popup box Plugin to version 6.3.0 or later, where the vulnerability has been patched.

Until the update can be applied, it is recommended to implement the mitigation rule provided by Patchstack to block attacks exploiting this XSS vulnerability.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-54192. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart