Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in [email protected] Anything Popup allows Reflected XSS. This issue affects Anything Popup: from n/a through 7.3.
We have discovered 13 live websites that are affected by CVE-2025-39397.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 13 live websites (100% of Anything Popup install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 4 websites | |
| 3 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 5 websites |
| .org | 2 websites |
| .co.jp | 1 websites |
| .co.uk | 1 websites |
| .com.au | 1 websites |
| .jp | 1 websites |
| .net | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************************.org | ***,*** | ||
| **.********.com | ***,*** | ||
| *****************.org | *,***,*** | ||
| *************.***.au | *,***,*** | ||
| ****************.com | **,***,*** | ||
| ****************.com | **,***,*** | ||
| ******.jp | **,***,*** | ||
| ******.com | **,***,*** | ||
| **************.com | **,***,*** | ||
| ********.net | **,***,*** |
FAQ