Impact
The PopupKit plugin is vulnerable because it fails to verify that a user is authorized to access the "/popup/logs" REST API endpoint. As a result, any authenticated user with a Subscriber role or higher can read analytics data that includes device types, browser information, countries, referrer URLs, and campaign metrics. The attacker can also delete this data. The core weakness is an access control flaw (CWE-862).
Affected Systems
WordPress sites that have the Popup builder plugin (ro xnor: Popup builder with Gamification, Multi‑Step Popups, Page‑Level Targeting, and WooCommerce Triggers) installed in versions 2.2.0 or earlier are affected. All versions up to and including 2.2.0 expose the "/popup/logs" REST endpoint, which is accessible to authenticated users with Subscriber-level access and above.
Risk and Exploitability
The CVSS score of 5.4 indicates a moderate risk, and the EPSS score of less than 1 % suggests a low exploitation probability at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, and the attack requires only a valid authenticated session with Subscriber privileges or higher, so it is relatively easy to exploit if a user can authenticate. Once the endpoint is accessed, attackers can exfiltrate sensitive analytics information and remove it, compromising confidentiality and integrity of site data.
OpenCVE Enrichment