Description
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with editor-level access and above, to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution. Exploitation requires that a valid Popup Maker Pro license is active on the target site and that Popup Maker Pro is not yet installed, as these conditions are necessary for the legacy v1/connect/info endpoint to issue the bearer token used to satisfy the install endpoint's only non-spoofable validation check.
Published: 2026-07-09
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress contains a missing authorization check that permits any authenticated user with editor-level permissions or higher to use the plugin’s REST API to install and activate an arbitrary WordPress plugin from a supplied URL. This flaw enables an attacker to execute arbitrary code on the server because the installed plugin runs with the same privileges as the WordPress installation. The weakness is classified as a missing authorization control (CWE‑862).

Affected Systems

Any WordPress site that runs the Popup Maker plugin by danieliser with a version equal to or older than 1.22.0 is vulnerable. The exploit requires that a valid Popup Maker Pro license is active on the site yet the Pro add‑on is not yet installed, allowing the legacy v1/connect/info endpoint to generate the bearer token that satisfies the install endpoint’s non‑spoofable check.

Risk and Exploitability

With a CVSS base score of 7.2, the vulnerability is considered high severity. The EPSS score of less than 1% indicates that real‑world exploitation is currently inf the attack can be performed remotely over HTTPS via the REST API once the attacker is authenticated as an editor or above. The condition that the Pro add‑on be absent means sites yet to install that add‑on are at risk. Since the flaw permits arbitrary plugin installation, any attacker who can create or edit content can inject malicious code, compromising the entire site. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 26, 2026 at 15:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Popup Maker plugin to any release newer than 1.22.0, which the REST API endpoints.
  • If an upgrade cannot be performed immediately, install the Popup Maker Pro add‑on; doing so removes the bearer‑token endpoint that the exploit depends on, thereby preventing the arbitrary plugin installation flow.
  • Restrict the plugin installation capabilities and the REST API endpoints so that only administrators can use them. This can be achieved by removing the 'activate_plugins' capability from editor roles or by configuring a security plugin to deny non‑administrator access to the /wp-json/ popup‑maker/v1 endpoints.
  • Add rules to block the popup-maker REST API paths (e.g., /wp-json/popup‑maker/v1/connect/install and /wp-json/v1/connect/info) for all users except administrators, thereby hardening the application against unauthorized install attempts.

Generated by OpenCVE AI on July 26, 2026 at 15:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Danieliser
Danieliser popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder
Wordpress
Wordpress wordpress
Vendors & Products Danieliser
Danieliser popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder
Wordpress
Wordpress wordpress

Thu, 09 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Description The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with editor-level access and above, to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution. Exploitation requires that a valid Popup Maker Pro license is active on the target site and that Popup Maker Pro is not yet installed, as these conditions are necessary for the legacy v1/connect/info endpoint to issue the bearer token used to satisfy the install endpoint's only non-spoofable validation check.
Title Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder <= 1.22.0 - Missing Authorization to Authenticated (Editor+) Arbitrary Plugin Installation
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Danieliser Popup Maker – Boost Sales, Conversions, Optins, Subscribers With The Ultimate Wp Popup Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-09T12:49:07.573Z

Reserved: 2026-05-18T15:45:24.005Z

Link: CVE-2026-8848

cve-icon Vulnrichment

Updated: 2026-07-09T12:49:02.483Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:00:04Z

Weaknesses