CVE Database /
CVE-2022-45819
CVE · Low
CVE-2022-45819 — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-45819
|
Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.0 |
Missing Authorization |
Low
3.5
|
< 1.18.0
|
1.18.0 |
2023-03-09 |
—
|
CVE-2022-45819
The Popup Maker plugin for WordPress before version 1.18.0 contains a vulnerability that allows authenticated users with contributor-level permissions or higher to toggle popup status without proper authorization checks. The save_popup_enabled_state function fails to validate whether the user has permission to modify a specific popup, enabling lower-privileged users to enable or disable popups they should not be able to edit.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings