Sceawere

Vulnerability Detail

CVE-2026-27537UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Popup by Supsystic XSS Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
7h ago
Vendor
supsystic
Product
Popup by Supsystic
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.11.2 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-13T14:16:56.380Z",
  "pubdate": "2026-08-13T14:16:56.380Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in the Popup by Supsystic plugin, specifically affecting versions 1.11.2 and prior. This security flaw enables remote attackers to inject malicious client-side scripts, typically JavaScript, into web pages rendered to unsuspecting end users visiting the affected WordPress site. The vulnerability stems from improper neutralization of user-supplied input before rendering it back to the client. Successful exploitation of this vulnerability can lead to severe security implications, including session hijacking, redirection to malicious external websites, theft of sensitive authentication cookies, and the unauthorized execution of arbitrary actions within the context of the victim's browser session. Because the attack vector is unauthenticated, any remote attacker over the network can trigger the execution of the payload without requiring prior access or specific user privileges on the target platform, provided they can craft and deliver the malicious payload to the vulnerable endpoint.",
  "technicalDetails": "The vulnerability is classified as a Cross-Site Scripting (XSS) issue originating from insufficient input sanitization and output encoding within the Popup by Supsystic plugin. Specifically, the vulnerable component fails to properly validate and sanitize parameters supplied via HTTP requests before reflecting them in the Document Object Model (DOM) or embedding them into generated HTML responses. This deficiency allows unauthenticated remote attackers to inject arbitrary HTML markup or JavaScript payloads into input fields or parameters processed by the plugin.\nThe attack flow proceeds as follows: First, the attacker crafts a malicious URL or HTTP request containing the unescaped JavaScript payload designed to target the vulnerable parameters handled by the Popup by Supsystic plugin. Second, the attacker induces a victim—either through social engineering, phishing, or direct interaction—to load the crafted URL or interact with the compromised endpoint over the network. Third, the vulnerable plugin processes the request and improperly embeds the unvalidated payload directly into the server response without employing adequate context-aware output encoding. Fourth, the victim's browser receives the HTTP response, parses the malicious payload as legitimate executable script content, and executes the injected JavaScript within the security context of the victim's active session on the target site.\nBecause the vulnerability requires no authentication or special privileges, network exposure is broad, affecting any public-facing WordPress installation running Popup by Supsystic versions 1.11.2 and below. Post-exploitation impact depends on the privileges of the victim interacting with the injected content; if an administrative user falls victim to the payload, the attacker can leverage the session to create new rogue administrator accounts, install malicious plugins, or execute arbitrary administrative tasks, leading to total compromise of the underlying WordPress environment."
}
CVE-2026-27537: Popup by Supsystic XSS Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere