CVE-2024-52434: WordPress Popup by Supsystic plugin <= 1.10.29 - Remote Code Execution (RCE) vulnerability
Published Nov 18, 2024
·Updated
Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.
Affected Software
1 affected component
Supsystic Popup Wordpress<=1.10.29
Event History
Nov 18, 2024
CVE Published
via MITRE·02:18 PM
Data Sourced
via MITRE·02:18 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52434?
CVE-2024-52434 has a high severity rating due to its potential for command injection.
2
How do I fix CVE-2024-52434?
To fix CVE-2024-52434, update the Supsystic Popup plugin to version 1.10.30 or later.
3
What systems are affected by CVE-2024-52434?
CVE-2024-52434 affects all versions of the Supsystic Popup plugin for WordPress up to 1.10.29.
4
What type of vulnerability is CVE-2024-52434?
CVE-2024-52434 is classified as a command injection vulnerability due to improper neutralization of special elements.
5
Can CVE-2024-52434 lead to remote code execution?
Yes, CVE-2024-52434 can allow for remote code execution if successfully exploited.