← back
CVE-2019-17574observed exploitation

CVE-2019-17574

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 9.4%
from disclosure to weapon
Published on NVDOct 14
VulnCheck+2079d
exploitation probability
9.4%top 5% of all CVEs
observed exploitation
yesVulnCheck
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
Affected products
n/a · n/a