Description
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
Published: 2026-10-02
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized configuration of callable functions leading to information disclosure and denial of service
Action: Immediate Patch
AI Analysis

Impact

WordPress users logged in with a low privilege level, such as Subscriber, can access the Popup Maker WP plugin management page because it does not enforce authorization checks. Those users can store display‑targeting values that are later invoked as zero‑argument PHP callables when a public page loads. This flaw permits arbitrary function execution without authentication, enabling an attacker to exfiltrate sensitive data from the site or trigger a denial of service by calling functions that consume resources.

Affected Systems

Any WordPress installation running the Popup Maker WP plugin versions 1.2.2.1 through 1.4.5 is affected. The vulnerability exists in the plugin’s management interface and the public page rendering process. No specific PHP environment or WordPress core version is further restricted by the data provided.

Risk and Exploitability

The developed CVSS score is 5.4, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a logged‑in user using a subscriber or similar low‑privileged role to modify configuration settings, after which the stored callable is executed on subsequent page loads. Exploitation would expose user data and potentially disrupt service, but it requires the attacker to be logged into the site. The absence of an EPSS score nor KEV listing does not negate the risk, as the flaw remains exploitable with a moderately high potential impact within the defined scope.

Generated by OpenCVE AI on October 2, 2026 at 14:02 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Popup Maker WP to the latest release that includes the authorization fix
  • Apply a role‑based access control restriction so that only administrators or editors can access the plugin’s management page
  • If an upgrade cannot be performed immediately, delete or sanitize existing display‑targeting values that store callable names and reset the plugin to its default safe configuration

Generated by OpenCVE AI on October 2, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-95

Fri, 02 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-95

Fri, 02 Oct 2026 07:15:00 +0000

Type Values Removed Values Added
Description The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
Title Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-02T10:54:10.542Z

Reserved: 2026-09-02T18:30:07.352Z

Link: CVE-2026-85005

cve-icon Vulnrichment

Updated: 2026-10-02T10:44:38.897Z

cve-icon NVD

Status : Received

Published: 2026-10-02T07:16:38.123

Modified: 2026-10-02T11:17:35.467

Link: CVE-2026-85005

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T14:15:15Z

Weaknesses