CVE-2026-85005: Popup Maker WP 1.2.2.1 - 1.4.5 - Subscriber+ Zero-Argument PHP Callable Invocation via Missing Authorization
The Popup Maker WP WordPress plugin through 1.4.5 does not perform authorization checks on several of its actions and exposes its management page to any logged-in user, allowing users with a low-privileged role such as Subscriber to store display-targeting values that are later invoked as zero-argument PHP callables on public page loads, leading to sensitive information disclosure and denial of service.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Popup Maker WP versions 1.2.2.1 through 1.4.5 are affected. Exploitation requires a logged-in account with a low-privileged role such as Subscriber, so sites that do not allow untrusted users to authenticate have a smaller exposure surface.
What does an attacker need to do to exploit it?
The attacker needs valid credentials for a low-privileged WordPress account. They can access the plugin management page and save display-targeting values that are subsequently invoked as zero-argument PHP callables when public pages load.
What is the likely impact of successful exploitation?
The documented impacts are disclosure of sensitive information and denial of service. The malicious values are triggered on public page loads, so the effects may occur when visitors request affected pages.
What can be done while a patch is unavailable?
Restrict or remove low-privileged logged-in accounts, particularly Subscriber accounts that are not required. Limiting access to untrusted authenticated users reduces the ability to reach the exposed management page and store the callable values.