CVE-2024-52434CWE-82

WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerability

Critical · published November 18, 2024

CVSS v3.1
9.1
EPSS
1%
Percentile
64.4
In the wild
Unconfirmed
What it is

🚨 A crafty command injection flaw lurks in Popup by Supsystic, allowing attackers to execute arbitrary commands on your server! 🔥 Think of it like a restaurant that allows any diner to sneak into the kitchen with a fake order — they could cook up anything they want, potentially ruining the whole meal. This vulnerability gives attackers that same kind of access, only to your server instead! If an attacker exploits this deserialization of untrusted data vulnerability, they could gain full control of your server environment. That means reading sensitive data, modifying files, or even launching further attacks without any barriers — absolutely devastating!

Put simply

Think of it like a restaurant that allows any diner to sneak into the kitchen with a fake order — they could cook up anything they want, potentially ruining the whole meal. This vulnerability gives attackers that same kind of access, only to your server instead! This vulnerability allows attackers to inject commands through deserialized data, exploiting the way Popup by Supsystic processes inputs. Any version from n/a through 1.10.29 is affected, enabling unauthorized execution of commands on the server.

What to do

If an attacker exploits this deserialization of untrusted data vulnerability, they could gain full control of your server environment. That means reading sensitive data, modifying files, or even launching further attacks without any barriers — absolutely devastating! To protect your system, immediately patch Popup by Supsystic to version 1.10.30 or later. Additionally, review your data handling processes to ensure that no untrusted data is processed without proper validation. Don't forget to monitor for unusual activity as an extra precaution! You've got this! Follow these steps, and you’ll be a security hero in no time! 🛡️

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.01137 · 64.4th percentile
Weakness
CWE-82 · Improper Neutralization of Script in Attributes of IMG Tags in a Web Page
Published
2024-11-18T14:18Z
EPSS history
Timeline
  • 18 NOV 14:18Z
    WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerability
    cvelistv5