Sceawere

Vulnerability Detail

CVE-2026-104023UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in Smart Popup

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.9
Creation Date
2h ago
Vendor
supsysticcom
Product
Smart Popup by Supsystic
Attack Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Smart Popup by Supsystic plugin for WordPress is vulnerable to generic SQL Injection via the 'sidx' parameter in all versions up to, and including, 1.13.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.9",
  "pubDate": "2026-10-10T06:16:38.590Z",
  "pubdate": "2026-10-10T06:16:38.590Z",
  "executiveSummary": "The Smart Popup by Supsystic plugin for WordPress is susceptible to a critical SQL Injection vulnerability affecting all versions up to and including 1.13.2.\nThe vulnerability arises from improper sanitization and lack of parameterized queries when handling user-supplied input through the 'sidx' parameter.\nThis flaw permits authenticated attackers with administrator-level privileges or higher to execute arbitrary SQL commands against the WordPress database.\nThe impact of a successful exploit is severe, as it grants unauthorized access to sensitive database content, potentially including user credentials, configuration data, and site metadata.\nRisk implications are high for site integrity and confidentiality, as the vulnerability facilitates unauthorized data extraction and database manipulation.\nExploitation requires the attacker to possess an active session with administrative capabilities, limiting the attack surface to trusted or compromised accounts but providing a significant escalation of authority within the database layer.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the Smart Popup by Supsystic plugin to implement secure database interaction practices, specifically regarding the 'sidx' parameter. The plugin code concatenates user-supplied input directly into an SQL query string without adequate escaping or the use of prepared statements.\nIn the affected versions up to 1.13.2, the application logic fails to apply sufficient input validation or sanitization routines on the 'sidx' parameter before passing it to the database query execution layer. This allows an attacker to break out of the intended query structure by injecting arbitrary SQL syntax.\nThe exploitation flow proceeds as follows: 1. The attacker authenticates to the WordPress dashboard with administrative privileges. 2. The attacker identifies an endpoint or request mechanism that processes the 'sidx' parameter. 3. The attacker crafts a malicious payload, such as a UNION-based or time-based SQL injection, to append unauthorized queries to the backend database transaction. 4. Due to the lack of query parameterization, the database engine executes the injected SQL commands as part of the original query context.\nBecause the input is not handled via sanitized methods such as the $wpdb->prepare() function, the database treats the malicious payload as trusted code. An attacker can leverage this behavior to perform 'UNION SELECT' statements to leak sensitive data from other tables, or utilize 'SLEEP()' commands to perform blind data exfiltration. The post-exploitation impact includes the full compromise of the underlying WordPress database, which may lead to total site takeover, credential theft, or the extraction of sensitive personal information stored within the plugin or the wider WordPress installation.\nThis vulnerability is restricted by the requirement of administrative authentication, meaning that the attacker must already be logged into a high-privileged account. However, this level of access is often a target for session hijacking or credential stuffing, making the vulnerability a significant vector for further escalation."
}
CVE-2026-104023: SQL Injection in Smart Popup (MEDIUM Severity, CVSS: 4.9) | Sceawere