Impact
The vulnerability allows an unauthenticated attacker to perform PHP Object Injection by sending crafted serialized data to the Popup by Supsystic plugin. This flaw can enable arbitrary code execution on the WordPress server, compromising confidentiality, integrity, and availability of the entire site. The weakness is classified as CWE-502. No mitigations are in place beyond patching, and exploitation requires no special privileges or prior access.
Affected Systems
WordPress installations running the Popup by Supsystic plugin version 1.13.0 or older are affected. All users who have the plugin installed and are accessible via the web should consider their instances vulnerable until updated.
Risk and Exploitability
The CVSS base score of 9.8 indicates critical severity, and the lack of an EPSS score shows no current estimation of exploitation probability, but the existence of a public advisory suggests potential for active exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely through the plugin’s unsanitized input endpoint, making it trivial to trigger execution without any authentication.
OpenCVE Enrichment