CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-52434

CVSS 9.1v3.1pub. 2024-11-18upd. 2026-04-23

Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.

🤖 AI Analysis
How it works

The vulnerability consists of unsafe deserialization of input data without proper validation (CWE-94, CWE-82). An attacker with administrator privileges can provide a specially crafted malicious serialized object that, when processed by the plugin, leads to execution of arbitrary system commands (command injection). Although high-level privileges are required (PR:H), the scope of the vulnerability extends beyond the application itself (Scope: Changed), which means it can affect the entire server system.

Impact

Successful exploitation of the vulnerability allows an attacker to execute arbitrary code remotely on the server (RCE), as well as completely compromise the confidentiality, integrity, and availability of the system, potentially leading to complete server takeover.

Mitigation & patch

The Popup by Supsystic plugin should be immediately updated to a version higher than 1.10.29. Detailed information about available patches can be found in the vendor's references and in the Patchstack database. Until the update is applied, it is recommended to deactivate the plugin.

Who is affected

Popup by Supsystic (popup-by-supsystic) plugin for WordPress in versions from its inception through 1.10.29 inclusive

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Supsystic Popup

    APP
    Supsystic
    ≤ 1.10.29
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2023-3186CRITICAL9.8PL ✓same product

Prototype pollution w pluginie Popup by Supsystic dla WordPress

CVE-2016-10915HIGH8.8same product

The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.

CVE-2023-39997MEDIUM5.3same product

Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configur...

CVE-2023-51353MEDIUM5.3same product

Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incor...

CVE-2023-46197MEDIUM5.3same product

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com ...