CVE · Low

CVE-2022-45819 — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-45819 Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.18.0 Missing Authorization Low 3.5 < 1.18.0 1.18.0 2023-03-09

CVE-2022-45819

The Popup Maker plugin for WordPress before version 1.18.0 contains a vulnerability that allows authenticated users with contributor-level permissions or higher to toggle popup status without proper authorization checks. The save_popup_enabled_state function fails to validate whether the user has permission to modify a specific popup, enabling lower-privileged users to enable or disable popups they should not be able to edit.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.