Zero-Day Advisory
Fortinet Discovers WordPress Popup Anything Plugin Cross-Site Scripting Vulnerability
Summary
Fortinet's FortiGuard Labs has discovered a cross-site scripting (XSS) vulnerability in WordPress Popup Anything Plugin.
Popup Anything is a modal popup plugin for WordPress websites that allows you to add highly customizable popup windows. It has over 50,000+ active installations.
A stored XSS vulnerability exists in Popup Anything Forms for WordPress 1.9.2.1 and below. A low privileged user (Contributor+) can inject arbitrary javascript code in popup draft form.
Solutions
FortiGuard Labs released the following FortiGate IPS signature which covers this specific vulnerability:WordPress.Plugin.Popup.Anything.XSS
Released Sep 17, 2021
Upgrade to Popup Anything version - 2.0.4 or later.
Timeline
Fortinet reported the vulnerability to WP OnlineSupport Team on September 1, 2021.
WP OnlineSupport Team confirmed the vulnerability on September 8, 2021.
WP OnlineSupport Team patched the vulnerability on October 14, 2021