CVE-2019-17574
14.10.2019, 14:15
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").Enginsight
Vendor | Product | Version |
---|---|---|
code-atlantic | popup_maker | 𝑥 < 1.8.13 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References