CVE-2026-102398: WordPress Popup by Supsystic plugin <= 1.13.1 - Cross Site Scripting (XSS) vulnerability
Published Sep 30, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in Popup by Supsystic <= 1.13.1 versions.
Affected Software
1 affected component
Supsystic Popup by Supsystic<=1.13.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Popup by Supsysticto a version that resolves this vulnerability.Fixed in 1.13.2
Event History
Sep 30, 2026
CVE Published
via MITRE·12:28 PM
Data Sourced
via MITRE·12:28 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or plugin privileges. Exploitation still requires user interaction, as reflected by the UI:R vector.
2
What impact can successful exploitation have?
Successful XSS can affect confidentiality, integrity, and availability at a low impact level. The scope is changed (S:C), meaning the vulnerable component may affect resources beyond its own security authority.
3
Which plugin versions are affected?
Popup by Supsystic versions 1.13.1 and earlier are affected. The provided data does not identify a fixed version.