Description
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an unauthenticated attacker to perform PHP Object Injection by sending crafted serialized data to the Popup by Supsystic plugin. This flaw can enable arbitrary code execution on the WordPress server, compromising confidentiality, integrity, and availability of the entire site. The weakness is classified as CWE-502. No mitigations are in place beyond patching, and exploitation requires no special privileges or prior access.

Affected Systems

WordPress installations running the Popup by Supsystic plugin version 1.13.0 or older are affected. All users who have the plugin installed and are accessible via the web should consider their instances vulnerable until updated.

Risk and Exploitability

The CVSS base score of 9.8 indicates critical severity, and the lack of an EPSS score shows no current estimation of exploitation probability, but the existence of a public advisory suggests potential for active exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely through the plugin’s unsanitized input endpoint, making it trivial to trigger execution without any authentication.

Generated by OpenCVE AI on August 18, 2026 at 16:13 UTC.

Remediation

Vendor Solution

Update the WordPress Popup by Supsystic Plugin to the latest available version (at least 1.13.1).


OpenCVE Recommended Actions

  • Update the WordPress Popup by Supsystic plugin to version 1.13.1 or later.
  • If the plugin is not required, deactivate or remove it from the site to eliminate the attack surface.
  • Monitor web server logs for malicious serialized payloads and block offending IPs to deter potential exploitation attempts.

Generated by OpenCVE AI on August 18, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Supsysticcom
Supsysticcom popup By Supsystic
Wordpress
Wordpress wordpress
Vendors & Products Supsysticcom
Supsysticcom popup By Supsystic
Wordpress
Wordpress wordpress

Tue, 18 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Description Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Title WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability
Weaknesses CWE-502
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Supsysticcom Popup By Supsystic
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-18T15:11:20.172Z

Reserved: 2026-08-12T14:09:17.491Z

Link: CVE-2026-73380

cve-icon Vulnrichment

Updated: 2026-08-18T15:10:05.249Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T15:17:06.003

Modified: 2026-08-20T12:48:31.843

Link: CVE-2026-73380

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:12:28Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data