S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Feb 1, 2024

CVE-2019-17574 Scanner

CVE-2019-17574 scanner - Broken Authentication vulnerability in Popup-Maker plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-17574
9.1
CVSS

An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Popup Maker plugin for WordPress is a popular tool used to easily create custom popups, modals, and opt-in forms on a website. It is utilized by businesses and individuals alike to improve their online user experience, capture leads, and increase conversions. With Popup Maker, users can easily customize the appearance, timing, and trigger conditions of their popups to fit the needs of their specific website.

However, the plugin was recently found to have a vulnerability in the form of CVE-2019-17574. This vulnerability allows an unauthenticated attacker to partially control the arguments of the do_action function to invoke specific popmake_ or pum_ methods. The attacker can take advantage of this to control the content and delivery of popmake-system-info.txt, also known as the "support debug text file". Essentially, an attacker could manipulate this file to execute malicious code on the website and potentially compromise user data.

When this vulnerability is exploited, it can lead to serious consequences for website owners and users. An attacker could potentially gain unauthorized access to sensitive information, steal personal data, or cause other malicious damage to the website. The overall user experience of the website may also suffer as a result, leading to brand damage and loss of credibility.

It's important to stay aware of potential vulnerabilities in any digital assets, including WordPress plugins like Popup Maker. Thanks to the pro features of the s4e.io platform, readers can quickly and easily scan their websites for vulnerabilities and take action to ensure their online security. Protecting your digital assets is essential for ensuring a safe and positive user experience for your audience.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that can be taken:

  • Update to the latest version of the Popup Maker plugin (1.8.13 or later) to patch the vulnerability
  • Regularly monitor site logs for any suspicious activity related to the Popup Maker plugin
  • Implement a web application firewall (WAF) to block any attempts to exploit this vulnerability
  • Restrict access to the popmake-system-info.txt file to authorized personnel only
  • Utilize strong passwords for all website accounts and regularly change them for added security

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-17574 scanner - Broken Authentication vulnerability in Popup-Maker plugin for WordPress S4E