Impact
Unauthenticated broken authentication exists in the WordPress Popup by Supsystic plugin versions 1.13.0 and below. A user without valid credentials can leverage the vulnerability to impersonate administrative accounts, modify settings, or execute arbitrary actions via the plugin interface. This weakness, identified as CWE-288, effectively removes user authentication checks that isolate privileged operations.
Affected Systems
The vulnerability affects the Popup by Supsystic plugin from the vendor supsystic. Any WordPress installation running a version of the plugin that is equal to or older than 1.13.0 is susceptible. No other products or vendors are indicated as affected in the available data.
Risk and Exploitability
The CVSS score of 9.1 signals a high severity flaw. Because the EPSS score is not available and the issue is not listed in CISA’s KEV catalog, the exploitation likelihood cannot be precisely quantified, yet the high CVSS suggests significant potential. The likely attack vector is through normal web traffic to the plugin’s administrative interface, requiring no special conditions beyond an unauthenticated HTTP request.
OpenCVE Enrichment