CVE-2026-73380: WordPress Popup by Supsystic plugin <= 1.13.0 - PHP Object Injection vulnerability
Published Aug 18, 2026
·Updated
Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.
Affected Software
1 affected component
WordPress Popup by Supsystic<=1.13.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Popup by Supsysticto a version that resolves this vulnerability.Fixed in 1.13.1
Event History
Aug 18, 2026
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are exposed?
Sites running Popup by Supsystic version 1.13.0 or earlier are affected according to the available information. The issue is exploitable without authentication, so exposure is not limited to logged-in WordPress users.
2
What does an attacker need to exploit it?
An attacker does not need an account or user interaction to exploit this issue. The reported impact includes high confidentiality, integrity, and availability impact.