CVE-2025-9856 | Popup Builder Plugin up to 4.4.1 on WordPress Shortcode sg_popup cross site scripting (EUVD-2025-203244)
A vulnerability, which was classified as problematic, was found in Popup Builder Plugin up to 4.4.1 on WordPress. This issue affects the function sg_popup of the component Shortcode Handler. Such manipulation leads to cross site scripting.
This vulnerability is documented as CVE-2025-9856. The attack can be executed remotely. There is not any exploit available.