ZeroHour

CVE-2026-88853

moderate

Privileged Stored XSS via Event Handlers in Regular Labs Modals Pro for Joomla

CVSS 4.0
7.5 high
EPSS
Published
()
Modified
AI analysis

Regular Labs Modals Pro for Joomla, in all versions before 17.0.0, contains a privileged stored cross-site scripting (XSS) flaw because its documented JavaScript event-handler feature (such as on-open and on-closed) is not restricted to trusted extension configuration. An authenticated attacker holding only author-level privileges can embed executable event code in ordinary article content, and that script then runs in the browser of any user — including a site administrator — who views the page. Successful exploitation gives the attacker script execution in a higher-privileged user's session, which can be leveraged for administrative actions such as content tampering, further account compromise, or site takeover. Sites running Modals Pro below 17.0.0 that allow non-trusted users to author articles are the most exposed; only the third-party extension is affected, not Joomla core. There is no evidence of exploitation in the wild, no public proof of concept, and the CVE is not on CISA's Known Exploited Vulnerabilities catalog.

What to do: Upgrade Modals Pro to version 17.0.0 or later, where the event-handler feature is reserved for trusted extension configuration. Until then, restrict article authoring to fully trusted staff and review existing articles for {modal} tags containing on-open/on-closed or other event attributes from untrusted contributors. Also audit author-level user accounts for suspicious or unauthorized registrations, since the flaw requires an authenticated author account to exploit.

Affected
Regular Labs (regularlabs.com) Modals Pro (Joomla extension)< 17.0.0
Estimated exposure
moderate≈1,000–10,000 Joomla sites (order of magnitude: thousands) — No active-install counts are published for this paid Joomla extension; the estimate derives from Joomla's roughly 1.5–2 million live sites and Modals Pro being a subscription product from one of the ecosystem's most popular vendors, whose…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.

Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.