First published: Mon Nov 18 2024(Updated: )
Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Supsystic Popup by Supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through 1.10.29.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Popup by Supsystic | <=1.10.29 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52434 has a high severity rating due to its potential for command injection.
To fix CVE-2024-52434, update the Supsystic Popup plugin to version 1.10.30 or later.
CVE-2024-52434 affects all versions of the Supsystic Popup plugin for WordPress up to 1.10.29.
CVE-2024-52434 is classified as a command injection vulnerability due to improper neutralization of special elements.
Yes, CVE-2024-52434 can allow for remote code execution if successfully exploited.