CVE · High

CVE-2026-8848 — Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-8848 Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder [popup-maker] < 1.23.0 Missing Authorization High 7.2 < 1.23.0 1.23.0 2026-07-08

CVE-2026-8848

The Popup Maker plugin, up to version 1.22.0, is susceptible to an authorization bypass vulnerability that allows authenticated users with editor-level permissions or higher to execute arbitrary actions, including installing and activating plugins from unauthorized sources. This can result in remote code execution if a valid Popup Maker Pro license is present but the Pro version has not been installed yet, as these conditions are required for the legacy v1/connect/info endpoint to provide the necessary bearer token.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.