CVE-2026-85005 PUBLISHED

Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization

Assigner: WPScan
Reserved: 02.09.2026 Published: 02.10.2026 Updated: 02.10.2026

The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
CVSS Score: 5.4

Product Status

Vendor Unknown
Product Popup Maker WP
Versions Default: unknown
  • affected from 1.2.2.1 to 1.4.5 (incl.)

Credits

  • Artus KG finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE