Description
WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more is prone to an information disclosure vulnerability. Attackers can exploit this issue to obtain sensitive information that may help in launching further attacks. WordPress Plugin Popup Maker-Popup for opt-ins, lead gen, & more version 1.8.11 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.13 or latest
References
https://blog.redyops.com/wordpress-plugin-popup-maker/
https://plugins.svn.wordpress.org/popup-maker/trunk/readme.txt
Related Vulnerabilities
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-3810)
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.5.2.727)
WordPress Plugin Newsletter Cross-Site Scripting (6.7.6)
Magento Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2019-7861)