Plugin Vulnerability Hub
Plugin 8 known issues Latest disclosed Nov 15, 2024

Smart Popup by Supsystic Vulnerabilities

Review known vulnerability records for the WordPress plugin Smart Popup by Supsystic (`popup-by-supsystic`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2024-52434, CVE-2024-31421 and CVE-2023-46197, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
8
High or Critical
3
Patch Coverage
100%
Last Updated
Apr 10, 2025
Related Security Guides

Use these guides while reviewing Smart Popup by Supsystic fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize Smart Popup by Supsystic remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
8
1. Match the Package
Confirm the installed WordPress plugin slug is popup-by-supsystic before acting on any CVE from this cluster.
2. Sort by Severity
Start with 3 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
8 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into Smart Popup by Supsystic CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
8
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2024-52434
Popup by Supsystic <= 1.10.29 - Authenticated (Admin+) Remote Code Execution
Remote Code Execution Versions up to 1.10.29 1.10.30 CVSS 9.1
CVE-2016-10915
Popup by Supsystic < 1.7.9 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions before 1.7.9 1.7.9 CVSS 8.8
CVE-2023-3186
Popup by Supsystic <= 1.10.18 - Prototype Pollution
Vulnerability Versions before 1.10.19 1.10.19 CVSS 7.1
CVE-2023-39997
Popup by Supsystic <= 1.10.19 - Cross-Site Request Forgery
Cross-Site Request Forgery Versions up to 1.10.19 1.10.20 CVSS 6.3
CVE-2021-24275
Popup by Supsystic <= 1.10.4 - Reflected Cross-Site Scripting
Cross-Site Scripting Versions up to 1.10.4 1.10.5 CVSS 6.1
CVE-2022-0424
Popup by Supsystic <= 1.10.8 - Sensitive Information Disclosure
Vulnerability Versions before 1.10.9 1.10.9 CVSS 5.3
CVE-2024-31421
Popup by Supsystic <= 1.10.27 - Missing Authorization
Vulnerability Versions up to 1.10.27 1.10.28 CVSS 4.3
CVE-2023-46197
Popup by Supsystic <= 1.10.19 - Missing Authorization to Sensitive Information Expos...
Sensitive Information Exposure Versions up to 1.10.19 1.10.20 CVSS 4.3
Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for Smart Popup by Supsystic so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
8 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
1 critical and 2 high severity findings.
Recent CVEs
CVE-2024-52434, CVE-2024-31421 and CVE-2023-46197
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for Smart Popup by Supsystic

Sorted by latest disclosure date so newly published issues surface first.

Plugin Critical Patched: Yes CVE-2024-52434
CVE-2024-52434: Popup by Supsystic <= 1.10.29 - Authenticated (Admin+) Remote Code Execution

The Popup by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.29. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the server.

Published
Nov 15, 2024
Patched Release
1.10.30
Affected Versions
Versions up to 1.10.29
Next Step
Update to 1.10.30 or newer if supported.
Plugin Medium Patched: Yes CVE-2024-31421
CVE-2024-31421: Popup by Supsystic <= 1.10.27 - Missing Authorization

The Popup by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.27. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an un...

Published
Apr 10, 2024
Patched Release
1.10.28
Affected Versions
Versions up to 1.10.27
Next Step
Update to 1.10.28 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-46197
CVE-2023-46197: Popup by Supsystic <= 1.10.19 - Missing Authorization to Sensitive Information Exposure

The Popup by Supsystic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.19 via the getWpCsvList action. This makes it possible for authenticated attackers with subscriber level access or higher to extract sensitive da...

Published
Oct 18, 2023
Patched Release
1.10.20
Affected Versions
Versions up to 1.10.19
Next Step
Update to 1.10.20 or newer if supported.
Plugin Medium Patched: Yes CVE-2023-39997
CVE-2023-39997: Popup by Supsystic <= 1.10.19 - Cross-Site Request Forgery

The Popup by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.19. This is due to missing or incorrect nonce validation for a subset of actions on the 'havePermissions' function. This makes it possible for unauthenti...

Published
Aug 11, 2023
Patched Release
1.10.20
Affected Versions
Versions up to 1.10.19
Next Step
Update to 1.10.20 or newer if supported.
Plugin High Patched: Yes CVE-2023-3186
CVE-2023-3186: Popup by Supsystic <= 1.10.18 - Prototype Pollution

The plugin Popup by Supsystic for WordPress is vulnerable to prototype pollution, which could make injecting malicious web scripts possible in some cases.

Published
Jun 23, 2023
Patched Release
1.10.19
Affected Versions
Versions before 1.10.19
Next Step
Update to 1.10.19 or newer if supported.
Plugin Medium Patched: Yes CVE-2022-0424
CVE-2022-0424: Popup by Supsystic <= 1.10.8 - Sensitive Information Disclosure

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

Published
Apr 18, 2022
Patched Release
1.10.9
Affected Versions
Versions before 1.10.9
Next Step
Update to 1.10.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2021-24275
CVE-2021-24275: Popup by Supsystic <= 1.10.4 - Reflected Cross-Site Scripting

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

Published
Apr 19, 2021
Patched Release
1.10.5
Affected Versions
Versions up to 1.10.4
Next Step
Update to 1.10.5 or newer if supported.
Plugin High Patched: Yes CVE-2016-10915
CVE-2016-10915: Popup by Supsystic < 1.7.9 - Cross-Site Request Forgery

The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.

Published
Sep 07, 2016
Patched Release
1.7.9
Affected Versions
Versions before 1.7.9
Next Step
Update to 1.7.9 or newer if supported.