Page Takeover
Page Takeover has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Page Takeover has a vendor fix available, so running the current release closes it.
All of these findings were reported by Nabil Irawan. Page Takeover is installed on roughly 200 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2025-31470Page Takeover <= 1.1.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Page Takeover
Author
FancyThemes
Promote Your Content in a Full-Screen Popup! Page Takeover allows you to create a stunning full-screen popup for your blog or website, without the need to know any HTML or CSS. Simply install the plugin, pick your colors, change the texts and your call-to-action, and load a distraction-free full-screen popup on your website. Promote Anything! Promote any post or page Promote any external URL Promote your recommended posts Promote your products or services Promote your special offers or coupon codes Promote your lead page or lead magnet Promote your podcast or webinar Promote your social media accounts Choose When Your Full-Screen Popup is Loaded Immediately After 5 seconds After 10 seconds After 30 seconds Choose How Often Your Full-Screen Popup is Shown Always Once per session Once every day Once every week Translations Translate Page Takeover into your language What’s Next If you like this plugin, then please leave us a good rating and review. Also take a look at our collection of free WordPress Themes and Best WordPress Hosting study, if you are looking to switch providers.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C