Sceawere
Vulnerability Detail
CVE-2026-85005UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Popup Maker Improper Authorization Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.4
- Creation Date
- 16h ago
- Vendor
- Unknown
- Product
- Popup Maker WP
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.4",
"pubDate": "2026-10-02T07:16:38.123Z",
"pubdate": "2026-10-02T07:16:38.123Z",
"executiveSummary": "The Popup Maker WordPress plugin, in versions through 1.4.5, is susceptible to an improper authorization vulnerability. This security flaw stems from a lack of adequate access control checks on specific administrative actions and the management interface itself.\nThe vulnerability permits authenticated users with minimal privileges, such as Subscribers, to access sensitive management functions and modify display-targeting configurations. By injecting arbitrary values into these settings, an attacker can force the application to invoke specific PHP functions upon public page loads.\nThis represents a significant security risk, potentially leading to sensitive information disclosure or application-wide denial of service (DoS). The requirement for the attacker to be authenticated as a logged-in user limits the scope to registered accounts, but does not mitigate the risk posed by compromised or malicious low-privileged accounts.\nThe vulnerability allows for remote execution of unintended logic within the WordPress environment, bypassing the intended security boundaries of the plugin. Organizations utilizing Popup Maker versions 1.4.5 or earlier are advised to upgrade immediately to prevent unauthorized configuration manipulation and subsequent service disruption.",
"technicalDetails": "The root cause of this vulnerability is a failure to enforce capabilities checks (e.g., current_user_can()) on administrative AJAX actions and management page registration within the Popup Maker plugin. The plugin fails to validate the authorization level of the user requesting these actions, allowing any authenticated user to interact with internal API endpoints meant exclusively for administrative personnel.\nThe exploitation flow begins with an authenticated low-privileged user (e.g., a Subscriber) navigating to or programmatically interacting with the plugin's management interface. Because the plugin does not verify if the user possesses 'manage_options' or similar administrative capabilities, the request is processed by the backend.\nThe attacker can manipulate the plugin's display-targeting settings by sending crafted POST requests to the insecurely exposed endpoints. Within these settings, the plugin allows the storage of metadata used to determine when a popup should be displayed. The vulnerability exists because these stored values are later treated as PHP callables (functions) during the rendering process on public-facing pages.\nWhen a legitimate visitor loads a page where the plugin is active, the plugin attempts to execute these stored targeting values as zero-argument functions using standard PHP dynamic execution patterns. By injecting the name of an existing, sensitive, or high-impact PHP function into the targeting metadata, an attacker can force the server to execute that function in the context of the WordPress application process.\nThis behavior facilitates two primary attack vectors: First, if an attacker provides a function that returns sensitive data, they may be able to capture or leak system configurations, database information, or environmental details. Second, an attacker can provide a function that crashes the script or triggers an infinite loop, resulting in a denial of service for the public-facing WordPress site.\nThe vulnerability is critical due to the ease of exploitation; it requires no advanced knowledge beyond identifying the AJAX action names, which are publicly discoverable in the plugin's source code. Because the vulnerable component is the core plugin architecture responsible for targeting logic, the entire site is rendered susceptible once an attacker gains minimal access to the management panel."
}