Description
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more version 1.8.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.13 or latest
References
https://blog.redyops.com/wordpress-plugin-popup-maker/
https://plugins.svn.wordpress.org/popup-maker/trunk/readme.txt
Related Vulnerabilities
Django Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0483)
WordPress Plugin IMPress for IDX Broker Cross-Site Scripting (3.0.5)
WordPress Plugin WP Cerber Security, Anti-spam & Malware Scan Security Bypass (9.0)
WordPress Plugin Infographic Maker-iList Unspecified Vulnerability (2.7.0)