๐Ÿ” CVE Alert

CVE-2026-85005

MEDIUM 5.4

Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.

Vendor unknown
Product popup maker wp
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for unknown popup maker wp

Be the first to know when new medium vulnerabilities affecting unknown popup maker wp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Popup Maker WP
1.2.2.1 โ‰ค 1.4.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/bddba59e-ab36-427f-9b21-98144bf783ff/

Credits

Artus KG WPScan