Popup Maker
cpe:2.3:a:wppopupmaker:popup_maker:*:*:*:*:wordpress:*:*
- <= 1.22.0
A vulnerability exists in the Popup Maker WordPress plugin, specifically in the 'Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder' version 1.22.0 and prior. The issue stems from an authorization bypass, where the plugin fails to properly verify user permissions. This flaw enables authenticated attackers with editor-level access or higher to exploit the legacy 'v1/connect/info' endpoint, provided they have a valid Popup Maker Pro license. The exploitation involves installing and activating any plugin from a URL controlled by the attacker, potentially leading to remote code execution.
Successful exploitation allows for the installation and activation of arbitrary plugins, which could be used to execute malicious code on the site.
To reproduce this vulnerability, an authenticated user with editor-level access or higher can send a request to the 'v1/connect/info' endpoint to obtain a bearer token. This token can then be used to bypass authorization checks on the 'upgrade/install' endpoint, where the attacker can specify a plugin to be installed from an external URL.
Users are advised to update the Popup Maker WordPress plugin to version 1.23.0 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.