Multiple Plugins <= (Various Versions) - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Magnific Popups JavaScript Library
Summary
| CVE | CVE-2024-5647 |
|---|---|
| State | PUBLISHED |
| Assigner | Wordfence |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-07-03 10:15:34 UTC |
| Updated | 2026-08-25 20:16:49 UTC |
| Description | Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled Magnific Popups library (version 1.1.0) in various versions due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. NOTE: This vulnerability was fixed in the upstream library (Magnific Popups version 1.2.0) by disabling the loading of HTML within certain fields by default. |
Risk And Classification
Primary CVSS: v3.1 6.4 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
EPSS: 0.002990000 probability, percentile 0.218900000 (date 2026-08-25)
Problem Types: CWE-79 | CWE-79 CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 6.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
| 3.1 | CNA | DECLARED | 6.4 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Blossomthemes | BlossomThemes Social Feed | affected 2.0.5 semver | Not specified |
| CNA | Sayful | Carousel Slider | affected 2.2.14 semver | Not specified |
| CNA | Divisupreme | Supreme Modules Lite Divi Theme Extra Theme And Divi Builder | affected 2.5.52 semver | Not specified |
| CNA | Robosoft | Robo Gallery Photo Image Slider | affected 3.2.22 semver | Not specified |
| CNA | Gutentor | Gutentor Gutenberg Blocks Page Builder For Gutenberg Editor | affected 3.4.9 semver | Not specified |
| CNA | Oceanwp | OceanWP | affected 3.6.0 semver | Not specified |
| CNA | Leevio | Happy Addons For Elementor | affected 3.12.2 semver | Not specified |
| CNA | Badhonrocks | Divi Torque Lite | affected 4.0.5 semver | Not specified |
| CNA | Elegant Themes | Divi Builder | affected 4.27.1 semver | Not specified |
| CNA | Elegant Themes | Divi | affected 4.27.1 semver | Not specified |
| CNA | Elegant Themes | Divi Extra | affected 4.27.1 semver | Not specified |
| CNA | Boldthemes | Bold Page Builder | affected 5.1.2 semver | Not specified |
| CNA | Wpdevteam | Essential Addons For Elementor Popular Elementor Templates Widgets | affected 6.0.4 semver | Not specified |
| CNA | Gn Themes | Shortcodes Ultimate Content Elements | affected 7.4.2 semver | Not specified |
| CNA | MuffinGroup | Betheme | affected 28.4 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| plugins.trac.wordpress.org/changeset/3328729/shortcodes-ultimate | [email protected] | plugins.trac.wordpress.org | |
| themes.trac.wordpress.org/changeset/244604/oceanwp | [email protected] | themes.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/bold-page-builder/trunk/content_elements_misc/js/jque... | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/changeset/3184626/addons-for-divi | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/changeset/3153781/bold-page-builder | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/browser/robo-gallery/trunk/js/robo_gallery.js | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/changeset/3154460/happy-elementor-addons | [email protected] | plugins.trac.wordpress.org | |
| support.muffingroup.com/changelog | [email protected] | support.muffingroup.com | |
| plugins.trac.wordpress.org/browser/essential-addons-for-elementor-lite/trunk/assets/fron... | [email protected] | plugins.trac.wordpress.org | |
| www.elegantthemes.com/api/changelog/divi.txt | [email protected] | www.elegantthemes.com | |
| plugins.trac.wordpress.org/changeset/3153700/essential-addons-for-elementor-lite | [email protected] | plugins.trac.wordpress.org | |
| plugins.trac.wordpress.org/changeset/3201991/robo-gallery | [email protected] | plugins.trac.wordpress.org | |
| www.wordfence.com/threat-intel/vulnerabilities/id/dae80fc2-3076-4a32-876d-5df1c... | [email protected] | www.wordfence.com | |
| plugins.trac.wordpress.org/changeset/3166204/carousel-slider | [email protected] | plugins.trac.wordpress.org | |
| www.elegantthemes.com/api/changelog/extra.txt | [email protected] | www.elegantthemes.com | |
| www.elegantthemes.com/api/changelog/divi-builder.txt | [email protected] | www.elegantthemes.com | |
| github.com/dimsemenov/Magnific-Popup/releases/tag/1.2.0 | [email protected] | github.com | |
| plugins.trac.wordpress.org/browser/shortcodes-ultimate/trunk/vendor/magnific-popup/magni... | [email protected] | plugins.trac.wordpress.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Webbernaut (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-06-05T00:00:00.000Z | Vendor Notified |
| CNA | 2025-07-02T00:00:00.000Z | Disclosed |
There are currently no legacy QID mappings associated with this CVE.