Impact
WordPress users logged in with a low privilege level, such as Subscriber, can access the Popup Maker WP plugin management page because it does not enforce authorization checks. Those users can store display‑targeting values that are later invoked as zero‑argument PHP callables when a public page loads. This flaw permits arbitrary function execution without authentication, enabling an attacker to exfiltrate sensitive data from the site or trigger a denial of service by calling functions that consume resources.
Affected Systems
Any WordPress installation running the Popup Maker WP plugin versions 1.2.2.1 through 1.4.5 is affected. The vulnerability exists in the plugin’s management interface and the public page rendering process. No specific PHP environment or WordPress core version is further restricted by the data provided.
Risk and Exploitability
The developed CVSS score is 5.4, indicating moderate severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. The likely attack vector is a logged‑in user using a subscriber or similar low‑privileged role to modify configuration settings, after which the stored callable is executed on subsequent page loads. Exploitation would expose user data and potentially disrupt service, but it requires the attacker to be logged into the site. The absence of an EPSS score nor KEV listing does not negate the risk, as the flaw remains exploitable with a moderately high potential impact within the defined scope.
OpenCVE Enrichment