Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total4
Critical1
High1
Medium2
Reset
Showing 1-4 of 4 records
Threat Entry Updated 2026-08-12

CVE-2026-18322 - Popup By Supsystic Plugin

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible…

PLUGIN Popup By Supsystic

CVE-2026-18322

HIGH CVSS 8.8 2026-08-05
Threat Entry Updated 2024-11-21

CVE-2023-3186 - Popup By Supsystic Plugin

The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.

PLUGIN Popup By Supsystic

CVE-2023-3186

CRITICAL CVSS 9.8 2023-07-17
Threat Entry Updated 2024-11-21

CVE-2022-0424 - Popup By Supsystic Plugin

The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users

PLUGIN Popup By Supsystic

CVE-2022-0424

MEDIUM CVSS 5.3 2022-05-09
Threat Entry Updated 2024-11-21

CVE-2021-24275 - Popup By Supsystic Plugin

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

PLUGIN Popup By Supsystic

CVE-2021-24275

MEDIUM CVSS 6.1 2021-05-05
Scroll to top