CVE-2025-15611Disclosure(ays-pro / popup_box)

LOWCVSS 5.4 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticated attackers to perform Cross-Site Request Forgery attacks. When an authenticated admin visits a malicious page, the attacker can create or modify popups with arbitrary JavaScript that executes in the admin panel and frontend.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • popup_box

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-07); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
popup_box

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-04-07: 2Mentions · 2026-04-19: 2Mentions · 2026-04-20: 1PoC Mentioned / Linked · 2026-04-20: 1Technical Details · 2026-04-07: 2Technical Details · 2026-04-19: 2Technical Details · 2026-04-20: 104-0704-1904-20
Signal classification2 categories
Disclosure
480.0%
PoC
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-04-072
Disclosure2
2026-04-192
Disclosure2
2026-04-201
PoC1
Full discourse5 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2025-15611-ays-popup-box-version-5-5-0-high-vulnerability-proof-of-concept CVE-2025-15611 #WordPress plugin #vulnerability ays-popup-box #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    A Proof‑of‑Concept for CVE‑2025‑15611 targeting the AYS Popup Box WordPress plugin (v5.5.0) has been published, highlighting a high‑severity vulnerability; no active exploitation or patch is currently mentioned.

    00000228
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-15611 The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticat… https://www.cve.org/CVERecord?id=CVE-2025-15611 ----- Traducción: CVE-2025-15611 El … http://infoflow.cloud`

    Post summary

    CVE-2025-15611 is a disclosed authentication bypass in the Popup Box WordPress plugin (versions prior to 5.5.0) due to improper nonce validation; no PoC, exploit code, or active exploitation is reported, nor is a patch mentioned.

    00000314
    72 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-15611 The Popup Box WordPress plugin before 5.5.0 does not properly validate nonces in the add_or_edit_popupbox() function before saving popup data, allowing unauthenticat… https://www.cve.org/CVERecord?id=CVE-2025-15611

    Post summary

    The post announces a CVE for the Popup Box WordPress plugin, highlighting a nonce validation flaw in a specific function, without providing PoC, exploit, or mitigation details.

    00000472
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2025-15611 Cross-Site Request Forgery in Popup Box WordPress Plugin Before 5.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-15611

    Post summary

    The text announces a CSRF vulnerability in the Popup Box WordPress Plugin affecting versions before 5.5.0, providing a link to detailed information.

    0000075
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2025-15611 - Popup Box AYS Pro < 5.5.0 - Admin+ Stored Cross-Site Scripting (XSS) via CSRF Intel Report: https://ift.tt/S7lfz3M

    Post summary

    A new disclosure alerts to CVE‑2025‑15611, a Stored XSS vulnerability in Popup Box AYS Pro versions below 5.5.0 via CSRF, accompanied by an Intel Report link.

    00000159
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appays-propopup_box-wordpress-

Explore more