CVE-2026-7850
WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute
CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th
The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.
| Vendor | unknown |
| Product | wp magnific popup |
| Published | Jun 17, 2026 |
| Last Updated | Jun 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown wp magnific popup
Be the first to know when new medium vulnerabilities affecting unknown wp magnific popup are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / WP Magnific Popup
0 โค 1.0
References
Credits
Pierre Rudloff WPScan