Modal Dialog

Modal Dialog has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2023 and 2026; all 3 are fixed as of September 2026. Their average CVSS score is 5.9, and the most serious one scores 7.2 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Scripting, behind 2 of the records (67%). Other recurring categories include Code Injection.

Every one of the 3 issues recorded for Modal Dialog has a vendor fix available, so running the current release closes all known holes.

3 independent researchers contributed these findings, one record each. Modal Dialog is installed on roughly 500 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.9.7.

Strategic Overview

Avg CVSSMedium
5.9/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all Modal Dialog vulnerabilities before they are exploited.

Highest severity on recordCVSS 7.2CVE-2026-32367

Modal Dialog <= 3.5.16 - Authenticated (Admin+) Remote Code Execution

Read the full analysis

Vulnerability Records

3 records
Modal Dialog banner
Latestv3.5.17
4.4(16)
88/100
Last Updated
2026-02-15 (7mo ago)
Active Installs
500+
Downloads
148,892
Requires WP
2.8+
Requires PHP
0+
Tested up to
WP 6.9.7
Created
2010-04-08 (17y ago)

The purpose of this plugin is to allow users to create one or more modal dialog(s) / pop-up window(s) that will appear when a user visits their site. The number of times that these can load is configurable. They can load content from external sites or custom HTML code into the dialog. This plugin can be used to invite people to register to a newsletter, respond to a survey, or simply welcome come to a site upon their first visit. You can try it out in a temporary copy of WordPress here.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C