WordPress Plugin Vulnerabilities
Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization
Description
The plugin does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
ACCESS CONTROLS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Artus KG
Submitter
Artus KG
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-29 (about 2 days ago)
Added
2026-09-22 (about 9 days ago)
Last Updated
2026-09-22 (about 9 days ago)