S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Dec 2, 2025

CVE-2024-6555 Scanner

CVE-2024-6555 Scanner - Information Disclosure vulnerability in WP Popups - WordPress Popup builder plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6555
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The WP Popups – WordPress Popup builder plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.2.0.1. This is due the plugin utilizing mobiledetect without preventing direct access to the files. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
WP Popups – WordPress Popup builderby timersys
0
wp_popupsby timersys
0
Updated Aug 22, 2026View on NVD →
Detail

WP Popups is a widely utilized plugin for creating popups on WordPress websites. Its user-friendly interface allows website administrators to design and manage popups efficiently. The plugin is often used by marketing teams to engage visitors through newsletters or promotional content. Developers also integrate this plugin to enhance user interaction on the site. It is compatible with a range of WordPress themes and is supported by a vast WordPress community. In summary, WP Popups is a versatile tool aimed at improving user engagement and boosting content visibility.

Information disclosure vulnerabilities occur when applications unintentionally reveal sensitive data. In the case of WP Popups, a specific vulnerability was identified that enables unauthorized users to gain access to server file paths. This flaw can be exploited without requiring authentication or any specific conditions. It becomes a stepping stone for attackers aiming to plan more sophisticated attacks on susceptible systems. Such vulnerabilities are critical as they expose internal architecture details inadvertently. Consequently, early detection and patching are necessary to prevent exploitation.

The vulnerability in WP Popups resides in using an unprotected endpoint that results in full path disclosure. When a specific endpoint is accessed, the server inadvertently leaks server path information. The vulnerable endpoint is located at `/wp-content/plugins/wp-popups-lite/src/vendor/mobiledetect/mobiledetectlib/export/exportToJSON.php`. There are no restrictions to access this endpoint, making it an easy target for automated scans. Using the endpoint, attackers can fetch a JSON file revealing server paths. Regular updates and secured coding practices can mitigate such vulnerabilities.

Potential exploitation of this vulnerability can lead to attackers gaining insights into the server's directory structure. With knowledge of server paths, attackers can escalate their attacks, possibly leading to directory traversal or other exploitation tactics. An informed attacker, equipped with such information, may target specific files or directories furthering information leakage. In worst-case scenarios, subsequent exploits may result in data breaches. Securing and consistently patching plugins remains crucial to protecting sensitive data.

REFERENCES

Solution Advice
  • Update to WP Popups version 2.2.0.2 or later.
  • Apply access restrictions to sensitive endpoints.
  • Ensure proper validation and sanitization of requests.
  • Regularly review and update plugin configurations.
  • Implement security best practices in your WordPress environment.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.