漏洞描述
An issue was discovered in the Popup Maker plugin before 1.8.13 for WordPress. An unauthenticated attacker can partially control the arguments of the do_action function to invoke certain popmake_ or pum_ methods, as demonstrated by controlling content and delivery of popmake-system-info.txt (aka the "support debug text file").
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
wpscan.comhttps://wpscan.com/vulnerability/9907↗web.archive.orghttps://web.archive.org/web/20191128065954/https://blog.redyops.com/wordpress-plugin-popup-maker/↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2019-17574↗github.comhttps://github.com/PopupMaker/Popup-Maker/blob/master/CHANGELOG.md↗wpvulndb.comhttps://wpvulndb.com/vulnerabilities/9907↗