CVE-2026-85004
Popup Maker WP <= 1.4.5 - Subscriber+ Missing Authorization via sgpm_connect
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.
| Vendor | unknown |
| Product | popup maker |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown popup maker
Be the first to know when new unknown vulnerabilities affecting unknown popup maker are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Popup Maker
0 โค 1.4.5
References
Credits
Artus KG WPScan