CVE-2025-14441: Roxnor Popup Builder With Gamification, Multi-Step Popups, Page-Level Targeting, And Woocommerce Triggers

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

The Popupkit plugin for WordPress is vulnerable to arbitrary subscriber data deletion due to missing authorization on the DELETE `/subscribers` REST API endpoint in all versions up to, and including, 2.2.0. This is due to the `permission_callback` only validating wp_rest nonce without checking user capabilities. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete arbitrary subscriber records.

Affected products

  • Roxnor Popup Builder With Gamification, Multi-Step Popups, Page-Level Targeting, And Woocommerce Triggers: up to and including 2.2.0

Published 2026-01-06. Last modified 2026-06-17.