CVE-2023-3186: Supsystic Popup < 1.10.19 - Prototype Pollution
Published Jul 17, 2023
·Updated
The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.
Affected Software
1 affected component
Supsystic Popup Wordpress<1.10.19
Event History
Jul 17, 2023
CVE Published
via MITRE·01:29 PM
Data Sourced
via MITRE·01:29 PM
DescriptionWeakness
Data Sourced
02:15 PM
DescriptionWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for the Popup by Supsystic WordPress plugin?
The vulnerability ID for the Popup by Supsystic WordPress plugin is CVE-2023-3186.
2
What is the severity rating of CVE-2023-3186?
CVE-2023-3186 has a severity rating of 9.8 (Critical).
3
What is the affected software for CVE-2023-3186?
The affected software for CVE-2023-3186 is the Popup by Supsystic WordPress plugin before version 1.10.19.
4
What is the description of CVE-2023-3186?
CVE-2023-3186 is a prototype pollution vulnerability in the Popup by Supsystic WordPress plugin that allows an attacker to inject arbitrary properties into Object.prototype.
5
Is there a fix available for CVE-2023-3186?
Yes, a fix for CVE-2023-3186 is available in version 1.10.19 or later of the Popup by Supsystic WordPress plugin.