PT-2019-15207 · WordPress · Popup Maker

Ilias Dimopoulos

·

Published

2019-10-14

·

Updated

2025-09-25

·

CVE-2019-17574

CVSS v3.1
9.1
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

**Name of the Vulnerable Software and Affected Versions**

Popup Maker plugin versions prior to 1.8.13

**Description**

An issue allows an unauthenticated attacker to partially control the arguments of the `do action` function, invoking certain `popmake ` or `pum ` methods. This can be used to control content and delivery of the support debug text file, `popmake-system-info.txt`.

**Recommendations**

For versions prior to 1.8.13, update to version 1.8.13 or later to resolve the issue.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2019-17574

Affected Products

Popup Maker