PT-2026-56735 · WordPress · Popup Maker

·

CVE-2026-8848

·

Published

2026-07-09

·

Updated

2026-07-09

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder versions prior to 1.22.1
Description An authorization bypass exists because the plugin fails to properly verify if a user is authorized to perform specific actions. Authenticated attackers with editor-level access or higher can exploit this to install and activate an arbitrary plugin from a URL under their control, which can lead to remote code execution. This exploitation is possible if a valid Popup Maker Pro license is active on the site and Popup Maker Pro is not yet installed, as these conditions allow the legacy '/v1/connect/info' endpoint to issue a bearer token required to bypass the validation check of the install endpoint.
Recommendations Update to a version newer than 1.22.0.

Fix

RCE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8848

Affected Products

Popup Maker