Title: XPath injection
Last modified: December 26, 2023

---

# XPath injection

 *  Resolved [WPninja](https://wordpress.org/support/users/rohitsapna/)
 * (@rohitsapna)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/xpath-injection/)
 * The URL path filename appears to be vulnerable to XPath injection attacks. The
   payload ‘ was submitted in the URL path filename, and an XPath error message 
   was returned.
   /wpcontent/plugins/popupmaker/assets/js/site.min.js

Viewing 2 replies - 1 through 2 (of 2 total)

 *  Plugin Author [Daniel Iser](https://wordpress.org/support/users/danieliser/)
 * (@danieliser)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/xpath-injection/#post-17302485)
 * [@rohitsapna](https://wordpress.org/support/users/rohitsapna/) – Can you please
   submit a ticket on our website with full details? I’m not even sure I understand
   what your claiming or how it could be attacked without more context, and best
   to not disclose it publicly right away if there really is an issue, at least 
   until the patch is released to the masses.
 * [https://wppopupmaker.com/report-security-vulnerability/](https://wppopupmaker.com/report-security-vulnerability/)
 *  Plugin Author [Daniel Iser](https://wordpress.org/support/users/danieliser/)
 * (@danieliser)
 * [2 years, 3 months ago](https://wordpress.org/support/topic/xpath-injection/#post-17302490)
 * Also, our plugin file path would be popup-maker, not popupmaker, so I’m really
   not sure what I’m looking at. Look forward to your email.

Viewing 2 replies - 1 through 2 (of 2 total)

The topic ‘XPath injection’ is closed to new replies.

 * ![](https://ps.w.org/popup-maker/assets/icon-256x256.gif?rev=3097653)
 * [Popup Maker - Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder](https://wordpress.org/plugins/popup-maker/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/popup-maker/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/popup-maker/)
 * [Active Topics](https://wordpress.org/support/plugin/popup-maker/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/popup-maker/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/popup-maker/reviews/)

 * 3 replies
 * 2 participants
 * Last reply from: [Daniel Iser](https://wordpress.org/support/users/danieliser/)
 * Last activity: [2 years, 3 months ago](https://wordpress.org/support/topic/xpath-injection/#post-17302490)
 * Status: resolved