Sceawere
Vulnerability Detail
CVE-2026-85004UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Popup Maker Improper Access Control
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 17h ago
- Vendor
- Unknown
- Product
- Popup Maker
- Attack Type
- CWE-284 Improper Access Control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The Popup Maker WordPress plugin through 1.4.5 does not perform a capability check on one of its account-connection actions, only verifying a nonce, allowing authenticated users with minimal privileges such as Subscribers to overwrite a site-wide Popup Maker WordPress plugin through 1.4.5 option (the linked service account and API configuration) that should only be modifiable by administrators.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-02T06:16:41.760Z",
"pubdate": "2026-10-02T06:16:41.760Z",
"executiveSummary": "The Popup Maker WordPress plugin, in versions through 1.4.5, contains a critical security vulnerability stemming from improper access control within its account-connection functionality. The vulnerability is classified as an authorization bypass where the plugin fails to implement necessary capability checks for sensitive administrative actions.\nSpecifically, the application performs a nonce check but neglects to verify the user's role or capabilities before permitting updates to global plugin settings. This allows authenticated users with minimal privileges, such as Subscribers, to modify the site-wide API configuration and linked service account settings.\nThe risk implication is significant, as an attacker with low-level access can perform unauthorized configuration changes that are intended exclusively for administrative personnel. By manipulating these settings, an attacker could potentially facilitate service hijacking, redirect API traffic, or integrate unauthorized third-party services with the target WordPress installation.\nExploitation is straightforward for any authenticated user, as the flaw relies on the absence of server-side authorization checks rather than complex technical bypassing. Organizations using affected versions are at risk of unauthorized administrative configuration changes.",
"technicalDetails": "The root cause of this vulnerability lies in an insecure implementation of an account-connection handler within the Popup Maker plugin. During the processing of AJAX or POST requests related to service account integration, the plugin architecture implements a nonce validation as the sole security barrier. While the nonce effectively mitigates cross-site request forgery (CSRF) attempts, it does not confirm that the user triggering the request possesses the 'manage_options' or equivalent administrative capabilities required to modify system-level configurations.\nIn WordPress plugin development, any function that alters global plugin settings must be protected by a capability check—typically implemented via 'current_user_can('manage_options')'—to ensure that the requester is authorized to perform administrative tasks. In this specific instance, the vulnerable component omits this check entirely. Consequently, when an authenticated Subscriber session initiates a request to the affected endpoint, the server-side code validates the existence of the nonce and proceeds to execute the write operation to the database.\nThe attack flow proceeds as follows: First, the attacker, logged in with minimal privileges, identifies the specific request structure and the nonce required for the account-connection action. Nonces in WordPress are often accessible to authenticated users via the DOM or specific localized JavaScript variables. Second, the attacker crafts a malicious request payload containing their own or an attacker-controlled service account identifier, API keys, or configuration parameters.\nThird, the attacker transmits this request to the server. Because the server only validates the integrity of the request via the nonce, it interprets the request as a legitimate administrative action. Finally, the plugin updates the database entry for the 'Popup Maker' service account configuration with the attacker-supplied data.\nThe post-exploitation impact allows the attacker to redirect API communications through an endpoint of their choosing. This could lead to a 'man-in-the-middle' scenario for any data transmitted by the plugin to third-party services, potential sensitive data exposure, or the total compromise of the plugin's integration features. Because the configuration is site-wide, the modification affects the entire WordPress installation, effectively escalating the attacker's influence over the site's external connectivity and plugin-managed assets."
}