AI Score
Confidence
High
EPSS
Percentile
73.5%
The slick-popup plugin before 1.7.2 for WordPress has a hardcoded OmakPass13# password for the slickpopupteam account, after a Subscriber calls a certain AJAX action.
wordpress.org/plugins/slick-popup/#developers
wpvulndb.com/vulnerabilities/9317
www.wordfence.com/blog/2019/05/privilege-escalation-flaw-present-in-slick-popup-plugin/