PT-2019-15207 · WordPress · Popup Maker

Ilias Dimopoulos

·

Published

2019-10-14

·

Updated

2025-11-29

·

CVE-2019-17574

CVSS v3.1

9.1

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Popup Maker plugin versions prior to 1.8.13
Description An issue allows an unauthenticated attacker to partially control the arguments of the do action function, invoking certain popmake or pum methods. This can be used to control content and delivery of the support debug text file, popmake-system-info.txt.
Recommendations For versions prior to 1.8.13, update to version 1.8.13 or later to resolve the issue.

Exploit

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2019-17574

Affected Products

Popup Maker