Hard-coded credentials in Slick Popup: Contact Form 7 Popup Plugin - #VU18731
Published: June 10, 2019 / Updated: June 13, 2019
Slick Popup: Contact Form 7 Popup Plugin
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to privilege escalation flaw in the Slick Popup plugin that allows any user with Subscriber privileges to create an administrator account with default credentials. A remote attacker can then use the created account to take over the website.
Default credentials are:Username:slickpopupteam
Password:OmakPass13#