Impact
The Smart Popup by Supsystic plugin for WordPress contains a SQL Injection flaw (CWE‑89) that originates from unvalidated usage of the 'sidx' query parameter. An attacker who can authenticate with administrator level or higher privilege can inject arbitrary SQL statements into the existing query, enabling them to read or modify sensitive database information. The injection can be leveraged to extract usernames, passwords, content, and other protected data stored in the WordPress database.
Affected Systems
This vulnerability affects all installations of the Smart Popup by Supsystic plugin version 1.13.2 and earlier. The plugin is a WordPress extension that provides popup functionality on WordPress sites.
Risk and Exploitability
The CVSS score of 4.9 represents a moderate severity, but the attack requires authenticated access with administrative privileges, limiting the potential exploit audience. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited current exploitation activity. The likely attack vector is an authenticated admin user manipulating the 'sidx' parameter through the plugin’s administration interface or crafted web requests, potentially leading to data exfiltration or credential compromise.
OpenCVE Enrichment