CVE-2019-17574
code-atlantic popup_maker Authorization Bypass Through User-Controlled Key
Record summary
CVE-2019-17574 has a selected CVSS score of 9.1 (critical); EIP currently links 1 Nuclei template.
Description
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 23, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
popup_makerBrowse code-atlantic / popup_maker | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryCRITICALPopup-Maker < 1.8.12 - Broken AuthenticationCVSS 9.1
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
Impact
Unauthenticated attackers can gain administrative access to the WordPress site.
Remediation
Update Popup-Maker plugin to version 1.8.12 or later.
Source: ProjectDiscovery