What this page helps you verify fast
This hub clusters tracked records for Smart Popup by Supsystic so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
Review known vulnerability records for the WordPress plugin Smart Popup by Supsystic (`popup-by-supsystic`), including severity, CVE references, affected versions, and patch status.
Recent tracked CVEs on this page include CVE-2024-52434, CVE-2024-31421 and CVE-2023-46197, so operators can jump from disclosure to patch validation without scanning the full feed first.
Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.
Review patch cadence, privileged access, XML-RPC exposure, backups, and monitoring controls.
Use ownership, update testing, least privilege, and removal criteria to reduce plugin risk.
Compare scanner coverage for plugin CVEs, version detection, alert noise, and remediation workflow.
Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.
Affected range: Versions up to 1.10.29. Fixed version: 1.10.30.
Affected range: Versions before 1.7.9. Fixed version: 1.7.9.
Affected range: Versions before 1.10.19. Fixed version: 1.10.19.
Affected range: Versions up to 1.10.19. Fixed version: 1.10.20.
Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.
| Tracked CVE | Issue Type | Affected Versions | Fixed Version | CVSS |
|---|---|---|---|---|
|
CVE-2024-52434
Popup by Supsystic <= 1.10.29 - Authenticated (Admin+) Remote Code Execution
|
Remote Code Execution | Versions up to 1.10.29 | 1.10.30 | CVSS 9.1 |
|
CVE-2016-10915
Popup by Supsystic < 1.7.9 - Cross-Site Request Forgery
|
Cross-Site Request Forgery | Versions before 1.7.9 | 1.7.9 | CVSS 8.8 |
|
CVE-2023-3186
Popup by Supsystic <= 1.10.18 - Prototype Pollution
|
Vulnerability | Versions before 1.10.19 | 1.10.19 | CVSS 7.1 |
|
CVE-2023-39997
Popup by Supsystic <= 1.10.19 - Cross-Site Request Forgery
|
Cross-Site Request Forgery | Versions up to 1.10.19 | 1.10.20 | CVSS 6.3 |
|
CVE-2021-24275
Popup by Supsystic <= 1.10.4 - Reflected Cross-Site Scripting
|
Cross-Site Scripting | Versions up to 1.10.4 | 1.10.5 | CVSS 6.1 |
|
CVE-2022-0424
Popup by Supsystic <= 1.10.8 - Sensitive Information Disclosure
|
Vulnerability | Versions before 1.10.9 | 1.10.9 | CVSS 5.3 |
|
CVE-2024-31421
Popup by Supsystic <= 1.10.27 - Missing Authorization
|
Vulnerability | Versions up to 1.10.27 | 1.10.28 | CVSS 4.3 |
|
CVE-2023-46197
Popup by Supsystic <= 1.10.19 - Missing Authorization to Sensitive Information Expos...
|
Sensitive Information Exposure | Versions up to 1.10.19 | 1.10.20 | CVSS 4.3 |
Popup by Supsystic <= 1.10.29 - Authenticated (Admin+) Remote Code Execution
Popup by Supsystic < 1.7.9 - Cross-Site Request Forgery
Popup by Supsystic <= 1.10.18 - Prototype Pollution
Popup by Supsystic <= 1.10.19 - Cross-Site Request Forgery
Popup by Supsystic <= 1.10.4 - Reflected Cross-Site Scripting
Popup by Supsystic <= 1.10.8 - Sensitive Information Disclosure
Popup by Supsystic <= 1.10.27 - Missing Authorization
Popup by Supsystic <= 1.10.19 - Missing Authorization to Sensitive Information Exposure
This hub clusters tracked records for Smart Popup by Supsystic so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.
These recent records surface the CVE strings, patch cues, and direct report links most operators need first.
The Popup by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.29. This makes it possible for authenticated attackers, with Adm...
The Popup by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.27. This makes it poss...
The Popup by Supsystic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.19 via the getWpCsvList action. This makes it possible...
Sorted by latest disclosure date so newly published issues surface first.
The Popup by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.29. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.
The Popup by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.27. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an un...
The Popup by Supsystic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.19 via the getWpCsvList action. This makes it possible for authenticated attackers with subscriber level access or higher to extract sensitive da...
The Popup by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.19. This is due to missing or incorrect nonce validation for a subset of actions on the 'havePermissions' function. This makes it possible for unauthenti...
The plugin Popup by Supsystic for WordPress is vulnerable to prototype pollution, which could make injecting malicious web scripts possible in some cases.
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.