CVE-2026-8848
Last modified
CVE-2026-8848 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.22.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with editor-level access and above, to install and activate an arbitrary plugin from an attacker-controlled URL, leading to remote code execution. Exploitation requires that a valid Popup Maker Pro license is active on the target site and that Popup Maker Pro is not yet installed, as these conditions are necessary for the legacy v1/connect/info endpoint to issue the bearer token used to satisfy the install endpoint's only non-spoofable validation check.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| danieliser | Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder | <= 1.22.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-8848?
How severe is CVE-2026-8848?
How do I fix CVE-2026-8848?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8842The Google+ Link Name plugin for WordPress is vulnerable to …6.4
- CVE-2026-8843Creating a "2dsphere_bucket" index on a non-timeseries bucke…7.1
- CVE-2026-8844The Responsive Check plugin for WordPress is vulnerable to S…6.4
- CVE-2026-8845The Islamic Database plugin for WordPress is vulnerable to S…6.4
- CVE-2026-8846The Tuxquote plugin for WordPress is vulnerable to Stored Cr…6.4
- CVE-2026-8847The Dideo plugin for WordPress is vulnerable to Stored Cross…6.4
- CVE-2026-8850IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of serv…7.5
- CVE-2026-8851SOGo versions 5.12.7 and prior contains a SQL injection vuln…8.6
- CVE-2026-8852IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of serv…7.5
- CVE-2026-8853The MW WP Form plugin for WordPress is vulnerable to Stored …4.4
- CVE-2026-8854IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of serv…7.5
- CVE-2026-8855IBM HTTP Server 8.5, and 9.0 is vulnerable to remote code ex…9.8
Are you affected by CVE-2026-8848?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
