Impact
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress contains a missing authorization check that permits any authenticated user with editor-level permissions or higher to use the plugin’s REST API to install and activate an arbitrary WordPress plugin from a supplied URL. This flaw enables an attacker to execute arbitrary code on the server because the installed plugin runs with the same privileges as the WordPress installation. The weakness is classified as a missing authorization control (CWE‑862).
Affected Systems
Any WordPress site that runs the Popup Maker plugin by danieliser with a version equal to or older than 1.22.0 is vulnerable. The exploit requires that a valid Popup Maker Pro license is active on the site yet the Pro add‑on is not yet installed, allowing the legacy v1/connect/info endpoint to generate the bearer token that satisfies the install endpoint’s non‑spoofable check.
Risk and Exploitability
With a CVSS base score of 7.2, the vulnerability is considered high severity. The EPSS score of less than 1% indicates that real‑world exploitation is currently inf the attack can be performed remotely over HTTPS via the REST API once the attacker is authenticated as an editor or above. The condition that the Pro add‑on be absent means sites yet to install that add‑on are at risk. Since the flaw permits arbitrary plugin installation, any attacker who can create or edit content can inject malicious code, compromising the entire site. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment