Modal Dialog
Modal Dialog has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 2 disclosures.
The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Code Injection.
Every one of the 3 issues recorded for Modal Dialog has a vendor fix available, so running the current release closes all known holes.
3 independent researchers contributed these findings, one record each. Modal Dialog is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.
CVE-2026-32367Modal Dialog <= 3.5.16 - Authenticated (Admin+) Remote Code Execution
Read the full analysisVulnerability Records

Modal Dialog
Author
Yannick Lefebvre
The purpose of this plugin is to allow users to create one or more modal dialog(s) / pop-up window(s) that will appear when a user visits their site. The number of times that these can load is configurable. They can load content from external sites or custom HTML code into the dialog. This plugin can be used to invite people to register to a newsletter, respond to a survey, or simply welcome come to a site upon their first visit. You can try it out in a temporary copy of WordPress here.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C