Executive brief
Popup Maker is a popular WordPress plugin used to create marketing popups and opt-in forms. A security flaw allows authorized users with editor-level access to bypass security checks and install malicious software from an external source. This could allow an attacker to take full control of the website, potentially leading to data theft or a complete site shutdown.
Technical details
The Popup Maker plugin for WordPress (versions up to 1.22.0) contains a missing authorization check (CWE-862) in its REST API implementation. Specifically, the legacy v1/connect/info endpoint can be manipulated to issue a bearer token that satisfies the validation requirements of the install endpoint. An authenticated attacker with editor-level permissions or higher can use this token to install and activate an arbitrary plugin from a remote URL. This leads to Remote Code Execution (RCE) on the underlying server. Exploitation is contingent upon a valid Popup Maker Pro license being active on the site while the Pro version itself is not yet installed.
Affected products
- danieliser Popup Maker up to, and including, 1.22.0
Timeline
- 2026-07-09: advisory: NVD publication date
References
- https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/Controllers/RestAPI.php
- https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/RestAPI/Connect.php
- https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/RestAPI/Connect.php
- https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/RestAPI/Connect.php
- https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.21.5/classes/Services/Connect.php
- https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/Controllers/RestAPI.php
- https://plugins.trac.wordpress.org/browser/popup-maker/tags/1.22.0/classes/RestAPI/Connect.php