Unauthenticated PHP Object Injection in Popup by Supsystic Plugin
CVE-2026-73380
9.8CRITICAL
What is CVE-2026-73380?
This vulnerability allows unauthenticated attackers to exploit a PHP Object Injection flaw in the Popup by Supsystic plugin version 1.13.0. By manipulating serialized data, attackers can potentially execute arbitrary PHP code, leading to unauthorized access, data manipulation, or system compromise. It is crucial for users of the affected version to apply the latest security updates or patches to mitigate this risk.
Affected Version(s)
Popup by Supsystic <= 1.13.0