CVE Database /
CVE-2019-17574
CVE · Critical
CVE-2019-17574 — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.8.13
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2019-17574
|
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.8.13 |
Authorization Bypass Through User-Controlled Key |
Critical
9.1
|
< 1.8.13
|
1.8.13 |
2019-10-14 |
—
|
CVE-2019-17574
The Popup Maker plugin before version 1.8.13 contains a vulnerability where attackers can manipulate arguments passed to the do_action function during PUM_Site initialization, allowing them to invoke any method associated with actions beginning with popmake_ or pum_. This flaw enables execution of parameterless functions or functions accepting array arguments, such as PUM_Admin_Tools::sysinfo_download and PUM_Admin_Tools::sysinfo_display, without proper authorization.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings