CVE-2025-39397

WordPress Anything Popup plugin <= 7.3 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in [email protected] Anything Popup allows Reflected XSS. This issue affects Anything Popup: from n/a through 7.3.


We have discovered 13 live websites that are affected by CVE-2025-39397.

Run a Free Instant Scan




Affected Software

Product  Anything Popup
Category Wordpress Plugins
Vulnerable Domains13 live websites (100% of Anything Popup install base)
Vulnerable Versions
  • from 0 through 7.3
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 24, 2025
  • Updated - Apr 25, 2025

Credits

  • Dimas Maulana (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-39397
United States4 websites



Japan3 websites
Turkey2 websites
Australia1 websites
Germany1 websites
GB1 websites
India1 websites

Website Distribution by TLD

Number of websites using CVE-2025-39397
.com5 websites
.org2 websites
.co.jp1 websites
.co.uk1 websites
.com.au1 websites
.jp1 websites
.net1 websites

Websites affected by CVE-2025-39397

Top websites that are affected by CVE-2025-39397. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***************************.org United States***,***
**.********.com Germany***,***
*****************.org United States*,***,***
*************.***.au Australia*,***,***
****************.com United States**,***,***
****************.com Turkey**,***,***
******.jp Japan**,***,***
******.com United States**,***,***
**************.com Turkey**,***,***
********.net Japan**,***,***
See full domain list

FAQ

CVE-2025-39397 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Anything Popup
A total of 13 websites have been identified as vulnerable to CVE-2025-39397, based on global website indexing conducted by WebTechSurvey.
The Anything Popup is affected by the CVE-2025-39397 vulnerability.
Anything Popup versions up to and including 7.3 are vulnerable to CVE-2025-39397.