Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.
The vulnerability consists of unsafe deserialization of input data without proper validation (CWE-94, CWE-82). An attacker with administrator privileges can provide a specially crafted malicious serialized object that, when processed by the plugin, leads to execution of arbitrary system commands (command injection). Although high-level privileges are required (PR:H), the scope of the vulnerability extends beyond the application itself (Scope: Changed), which means it can affect the entire server system.
Successful exploitation of the vulnerability allows an attacker to execute arbitrary code remotely on the server (RCE), as well as completely compromise the confidentiality, integrity, and availability of the system, potentially leading to complete server takeover.
The Popup by Supsystic plugin should be immediately updated to a version higher than 1.10.29. Detailed information about available patches can be found in the vendor's references and in the Patchstack database. Until the update is applied, it is recommended to deactivate the plugin.
Popup by Supsystic (popup-by-supsystic) plugin for WordPress in versions from its inception through 1.10.29 inclusive
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSupsystic Popup
APPSupsystic≤ 1.10.29
Related vulnerabilities
Prototype pollution w pluginie Popup by Supsystic dla WordPress
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configur...
Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incor...
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com ...