Impact
Popup Maker for WordPress through version 1.4.5 fails to perform a capability check on the sgpm_connect account‑connection action, validating only a nonce. This oversight allows any authenticated user with minimal privileges—such as a Subscriber—to overwrite the site‑wide option that holds the linked service account and API configuration. By altering these settings, an attacker can reconfigure or disable key plugin functionality, potentially redirecting pop‑ups or exposing sensitive data.
Affected Systems
WordPress sites running the Popup Maker plugin, any version up through 1.4.5 inclusive. The plugin is listed as Unknown:Popup Maker in CNA data; no additional version granularity is specified.
Risk and Exploitability
The flaw permits modification of plugin configuration by non‑admin users, elevating privileges at the configuration level. Exploitation requires an authenticated account; the attack vector is internal and requires the attacker to be logged in as a Subscriber or similar low‑privilege role. EPSS score is not available and KEV is not listed, and no CVSS score is provided, but the potential for widespread service disruption or creation of a foothold makes the risk moderate to high in environments where subscriber accounts can be compromised or where low‑privilege users are not tightly controlled.
OpenCVE Enrichment