Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 02 Oct 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-200 CWE-284 CWE-95 |
Fri, 02 Oct 2026 07:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service. | |
| Title | Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-10-02T10:54:10.542Z
Reserved: 2026-09-02T18:30:07.352Z
Link: CVE-2026-85005
No data.
Status : Received
Published: 2026-10-02T07:16:38.123
Modified: 2026-10-02T07:16:38.123
Link: CVE-2026-85005
No data.
OpenCVE Enrichment
Updated: 2026-10-02T09:15:08Z