CVE-2025-54018
Description
Missing Authorization vulnerability in CreativeMindsSolutions CM Pop-Up banners cm-pop-up-banners allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CM Pop-Up banners: from n/a through <= 1.8.4.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Missing authorization in CM Pop-Up banners plugin (versions ≤1.8.4) allows unauthenticated attackers to exploit misconfigured access controls, enabling unauthorized actions.
Vulnerability
Overview The CM Pop-Up banners plugin for WordPress (versions through 1.8.4) contains a missing authorization vulnerability. The issue stems from incorrect access control security levels, allowing exploitation of broken access controls. This is classified as a Missing Authorization vulnerability (CWE-862). [1]
Exploitation
Method An attacker can exploit this vulnerability without authentication by sending crafted requests to the plugin. The lack of proper capability checks or nonce tokens means unprivileged users can execute actions that should require higher privileges. The vulnerability is present in all versions up to and including 1.8.4. [1]
Impact
Successful exploitation could allow an unprivileged attacker to perform unauthorized actions within the WordPress installation, such as modifying plugin settings or accessing restricted data. While the CVSS score is 4.3 (Medium), the vendor notes this is a low-severity impact and unlikely to be exploited in typical cases, though mass-exploit campaigns have been observed for similar vulnerabilities. [1]
Mitigation
The vulnerability has been patched in version 1.8.5. Users are strongly advised to update immediately. For Patchstack users, auto-updates can be enabled for vulnerable plugins. If updating is not possible, consulting with a hosting provider or web developer is recommended. [1]
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2<= 1.8.4+ 1 more
- (no CPE)range: <= 1.8.4
- (no CPE)range: <=1.8.4
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.