Extension WordPress
Vulnérabilités Smart Popup by Supsystic
Cette page rassemble les failles publiées pour Smart Popup by Supsystic, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Smart Popup by Supsystic
8 fiches
Popup by Supsystic <= 1.10.29 – Authenticated (Admin+) Remote Code Execution
The Popup by Supsystic plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.10.29. This makes it possible for authenticated attackers, with Administrator-level access and above, to execute code on the…
*-1.10.29
1.10.30
15/11/2024
Popup by Supsystic <= 1.10.27 – Missing Authorization
The Popup by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.10.27. This makes it possible for authenticated attackers, with subscriber-level access…
*-1.10.27
1.10.28
10/04/2024
Popup by Supsystic <= 1.10.19 – Missing Authorization to Sensitive Information Exposure
The Popup by Supsystic plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.10.19 via the getWpCsvList action. This makes it possible for authenticated attackers with subscriber level access or higher…
*-1.10.19
1.10.20
18/10/2023
Popup by Supsystic <= 1.10.19 – Cross-Site Request Forgery
The Popup by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.10.19. This is due to missing or incorrect nonce validation for a subset of actions on the 'havePermissions' function.…
*-1.10.19
1.10.20
11/08/2023
Popup by Supsystic <= 1.10.18 – Prototype Pollution
The plugin Popup by Supsystic for WordPress is vulnerable to prototype pollution, which could make injecting malicious web scripts possible in some cases.
[*, 1.10.19)
1.10.19
23/06/2023
Popup by Supsystic <= 1.10.8 – Sensitive Information Disclosure
The Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated attackers to call it and get the email addresses of subscribed users
[*, 1.10.9)
1.10.9
18/04/2022
Popup by Supsystic <= 1.10.4 – Reflected Cross-Site Scripting
The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue
*-1.10.4
1.10.5
19/04/2021
Popup by Supsystic < 1.7.9 – Cross-Site Request Forgery
The popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.
[*, 1.7.9)
1.7.9
07/09/2016
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.