Sploitus

CVE-2019-17574

1 known exploit for CVE-2019-17574

An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").

Affected products
Popup Maker
Code-atlantic Popup Maker
< 1.8.13
Fix
Available
CVSS 3.1
9.1 CRITICAL
EPSS
9.4% (95th percentile)
Weakness
CWE-639
NVD status
Modified
Published
2019-10-14
CVE-2019-17574 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2019-17574

Proof-of-concept code and exploit modules indexed by Sploitus