CVE-2023-39997: WordPress Popup by Supsystic plugin <= 1.10.19 - Broken Access Control Vulnerability
Published Dec 13, 2024
·Updated
Missing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsystic: from n/a through <= 1.10.19.
Affected Software
3 affected components
Supsystic Popup Wordpress<1.10.20
Supsystic Popup by Supsystic<=1.10.19
WordPress Popup by Supsystic<=1.10.19
Remediation
Information
Update the WordPress Popup by Supsystic plugin to the latest available version (at least 1.10.20).
Event History
Dec 13, 2024
CVE Published
via MITRE·02:24 PM
Data Sourced
via MITRE·02:24 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-39997?
CVE-2023-39997 has a medium severity rating due to its missing authorization vulnerability that allows improper access control.
2
How do I fix CVE-2023-39997?
To fix CVE-2023-39997, update Popup by Supsystic to the latest version beyond 1.10.19.
3
What is the impact of CVE-2023-39997?
CVE-2023-39997 can lead to unauthorized access to restricted functionalities on the affected Popup by Supsystic plugin.
4
Which versions of Popup by Supsystic are affected by CVE-2023-39997?
CVE-2023-39997 affects all versions of Popup by Supsystic up to and including version 1.10.19.
5
Is CVE-2023-39997 specific to WordPress?
Yes, CVE-2023-39997 specifically affects the Popup by Supsystic plugin for WordPress.