CVE-2019-17574
Popup-Maker <= 1.8.12 - Unauthenticated information disclosure
Severity Score
9.1
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
Se detectó un problema en el plugin Popup Maker en versiones anteriores a la 1.8.13 para WordPress. Un atacante no autenticado puede controlar parcialmente los argumentos de la función do_action para invocar ciertos métodos popmake_ o pum_, como lo demuestra el control del contenido y la entrega de popmake-system-info.txt (también conocido como "support debug text file").
*Credits:
Dimopoulos Elias
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2019-10-14 CVE Reserved
- 2019-10-14 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-10-07 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-287: Improper Authentication
- CWE-639: Authorization Bypass Through User-Controlled Key
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/PopupMaker/Popup-Maker/blob/master/CHANGELOG.md | Release Notes | |
https://wpvulndb.com/vulnerabilities/9907 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
http://blog.redyops.com/wordpress-plugin-popup-maker | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Code-atlantic Search vendor "Code-atlantic" | Popup Maker Search vendor "Code-atlantic" for product "Popup Maker" | < 1.8.13 Search vendor "Code-atlantic" for product "Popup Maker" and version " < 1.8.13" | wordpress |
Affected
|