Sceawere
Vulnerability Detail
CVE-2026-102398UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated XSS in Popup by Supsystic
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 3h ago
- Vendor
- supsystic
- Product
- Popup by Supsystic
- Attack Type
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-09-30T13:17:17.647Z",
"pubdate": "2026-09-30T13:17:17.647Z",
"executiveSummary": "Popup by Supsystic versions 1.13.1 and below are susceptible to an unauthenticated Cross-Site Scripting (XSS) vulnerability. This vulnerability arises from improper neutralization of user-supplied input before rendering it in the browser.\nSuccessful exploitation allows an unauthenticated, remote attacker to inject and execute arbitrary JavaScript code within the context of a victim's browser session. This can lead to session hijacking, unauthorized actions on behalf of the administrator, redirection to malicious domains, or the theft of sensitive data.\nBecause the vulnerability does not require authentication, it poses a significant risk to site integrity and user security. The attack is executable over the network by any visitor to the site, necessitating immediate remediation to prevent potential account takeovers or client-side attacks.\nThe vulnerability highlights a failure in input validation and output encoding mechanisms within the plugin's data processing pipeline, allowing malicious payloads to be stored or reflected in the application's interface.",
"technicalDetails": "The vulnerability exists due to insufficient sanitization and validation of input parameters within the Popup by Supsystic plugin. The application fails to properly encode or escape malicious user-supplied payloads before reflecting them back to the user's browser, enabling the execution of arbitrary JavaScript.\nIn a typical attack scenario, an attacker crafts a malicious URL containing a JavaScript payload within vulnerable input fields. When an unsuspecting user, such as an administrator, navigates to the crafted URL or interacts with a page where the payload is rendered, the payload executes in the context of the user's session.\nBecause this vulnerability is unauthenticated, the attacker does not need prior access to the system. The attack vector is strictly web-based, utilizing standard HTTP protocols to deliver the payload. Once the script executes, it operates with the privileges of the victim, allowing it to perform any action permitted by the victim's session, including modifying site settings, creating new administrative users, or exfiltrating browser-stored cookies and sensitive configuration data.\nThe root cause is a failure to implement robust output encoding (e.g., using WordPress functions like esc_html(), esc_attr(), or wp_kses()) for input handled by the plugin, allowing for the injection of script tags or attribute-based XSS vectors. The affected versions (<= 1.13.1) do not adequately sanitize data before it is rendered, leading to stored or reflected XSS depending on whether the payload is persisted in the database.\nPost-exploitation, the impact is severe. An attacker can achieve complete site compromise by leveraging the victim's authenticated session to execute administrative functions, deface the website, inject malicious redirects, or distribute malware to visitors."
}