๐Ÿ” CVE Alert

CVE-2026-7850

MEDIUM 5.9

WP Magnific Popup <= 1.0 - Author+ Stored XSS via href Attribute

CVSS Score
5.9
EPSS Score
0.0%
EPSS Percentile
0th

The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.

Vendor unknown
Product wp magnific popup
Published Jun 17, 2026
Last Updated Jun 17, 2026
Stay Ahead of the Next One

Get instant alerts for unknown wp magnific popup

Be the first to know when new medium vulnerabilities affecting unknown wp magnific popup are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / WP Magnific Popup
0 โ‰ค 1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/30f408dd-4b9a-438c-8dc4-c6daafe237fe/

Credits

Pierre Rudloff WPScan