Slick Popup <= 1.7.1 - Privilege Escalation

2019-05-28 00:00
Mikey Veenstra

Strategic Overview

Status
Patched in 1.7.2
Affected Version< 1.7.2
CVSS8.8High
CVECVE-2019-15867
View all Slick Popup: Contact Form 7 Popup Plugin vulnerabilities

Vulnerability Overview

The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.

Technical Analysis

REMEDIATION: Update to version 1.7.2, or a newer patched version --- IDENTIFIER: CWE-798 (Use of Hard-coded Credentials) The product contains hard-coded credentials, such as a password or cryptographic key.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C