
CVE-2025-53994 – WordPress JetPopup plugin <= 2.0.15 - Cross Site Scripting (XSS) Vulnerability
https://notcve.org/view.php?id=CVE-2025-53994
16 Jul 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup allows DOM-Based XSS. This issue affects JetPopup: from n/a through 2.0.15. The JetPopup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages ... • https://patchstack.com/database/wordpress/plugin/jet-popup/vulnerability/wordpress-jetpopup-plugin-2-0-15-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-53995 – WordPress JetPopup plugin <= 2.0.15.1 - Cross Site Scripting (XSS) Vulnerability
https://notcve.org/view.php?id=CVE-2025-53995
16 Jul 2025 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopup allows Stored XSS. This issue affects JetPopup: from n/a through 2.0.15.1. The JetPopup plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.0.15.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages... • https://patchstack.com/database/wordpress/plugin/jet-popup/vulnerability/wordpress-jetpopup-plugin-2-0-15-1-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2025-53993 – WordPress JetPopup <= 2.0.15 - Sensitive Data Exposure Vulnerability
https://notcve.org/view.php?id=CVE-2025-53993
16 Jul 2025 — Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetPopup allows Retrieve Embedded Sensitive Data. This issue affects JetPopup: from n/a through 2.0.15. The JetPopup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.15. This makes it possible for authenticated attackers, with Subscriber-level access and above, to extract sensitive user or configuration data. • https://patchstack.com/database/wordpress/plugin/jet-popup/vulnerability/wordpress-jetpopup-2-0-15-sensitive-data-exposure-vulnerability?_s_id=cve • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-201: Insertion of Sensitive Information Into Sent Data •

CVE-2025-26944 – WordPress JetPopup <= 2.0.11 - Broken Access Control Vulnerability
https://notcve.org/view.php?id=CVE-2025-26944
15 Apr 2025 — Missing Authorization vulnerability in NotFound JetPopup allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects JetPopup: from n/a through 2.0.11. The JetPopup plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.0.11. This makes it possible for unauthenticated attackers to perform an unauthorized action. • https://patchstack.com/database/wordpress/plugin/jet-popup/vulnerability/wordpress-jetpopup-2-0-11-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •