Impact
The vulnerability is an unauthenticated Cross Site Scripting flaw located in the Popup by Supsystic plugin for WordPress versions 1.11.2 and earlier. Attackers can inject arbitrary JavaScript into the plugin’s output, which could be used to deface the site, steal user cookies, or redirect visitors to malicious sites. This weakness stems from insufficient input validation on user‑controlled fields, corresponding to CWE‑79.
Affected Systems
The plugin is developed by Supsystic, and all releases up through 1.11.2 are affected. WordPress sites that have installed Popup by Supsystic 1.11.2 or any earlier release should view this as a compliance issue. No other vendors or products are listed as impacted.
Risk and Exploitability
With a CVSS score of 6.5, the flaw presents a moderate severity risk. The EPSS score is not available and the vulnerability is not part of CISA’s KEV catalog, but the unauthenticated nature means an attacker can exploit it without credentials, typically by embedding malicious content in a pop‑up or through crafted URLs. Administrators should treat it as a genuine threat until the plugin is patched.
OpenCVE Enrichment