CVE · Critical

CVE-2019-17574 — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.8.13

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-17574 Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.8.13 Authorization Bypass Through User-Controlled Key Critical 9.1 < 1.8.13 1.8.13 2019-10-14

CVE-2019-17574

The Popup Maker plugin before version 1.8.13 contains a vulnerability where attackers can manipulate arguments passed to the do_action function during PUM_Site initialization, allowing them to invoke any method associated with actions beginning with popmake_ or pum_. This flaw enables execution of parameterless functions or functions accepting array arguments, such as PUM_Admin_Tools::sysinfo_download and PUM_Admin_Tools::sysinfo_display, without proper authorization.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.