Unauthenticated Cross Site Scripting Vulnerability in Popup Plugin by Supsystic
CVE-2026-27537
6.5MEDIUM
What is CVE-2026-27537?
The Popup by Supsystic WordPress plugin is vulnerable to unauthenticated Cross Site Scripting (XSS), which allows attackers to inject malicious scripts into web pages. This can lead to session hijacking, defacement, and other attacks on users interacting with compromised popups. Proper validation of user inputs is critical to mitigate this vulnerability in versions up to 1.11.2.
Affected Version(s)
Popup by Supsystic <= 1.11.2