CVE-2019-17574

CRITICAL EXPLOITED NUCLEI

Popup Maker < 1.8.13 - Unauthenticated Authorization Bypass via do_action Function

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-17574 has been observed exploited in the wild (reported by VulnCheck KEV). A Nuclei detection template is also available.

Description

An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").

Nuclei Templates (1)

Popup-Maker < 1.8.12 - Broken Authentication
CRITICALVERIFIEDby DhiyaneshDK
Shodan: http.html:/wp-content/plugins/popup-maker/
FOFA: body=/wp-content/plugins/popup-maker/

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
http://blog.redyops.com/wordpress-plugin-popup-maker/
Third Party Advisory x_refsource_misc
https://wpvulndb.com/vulnerabilities/9907

Scores

CVSS v3 9.1
EPSS 0.0923
EPSS Percentile 94.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Details

VulnCheck KEV 2025-06-23
CWE
CWE-639
Status published
Products (1)
code-atlantic/popup_maker < 1.8.13
Published Oct 14, 2019
Tracked Since Feb 18, 2026