CVE-2026-73381: WordPress Popup by Supsystic plugin <= 1.13.0 - Broken Authentication vulnerability
Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Popup by Supsysticto a version that resolves this vulnerability.Fixed in 1.13.1
Event History
Frequently Asked Questions
Which deployments are exposed to this vulnerability?
Any site running Supsystic WordPress Popup version 1.13.0 or earlier is identified as affected. The issue is remotely exploitable without authentication or user interaction.
What does an attacker need to exploit it?
An attacker does not need a WordPress account, elevated privileges, or victim interaction. The published severity vector indicates network access with low attack complexity.
What should teams do if they are running an affected version?
Upgrade the plugin to a version later than 1.13.0 when one is available. The provided data does not identify a workaround or mitigation for deployments that cannot be patched immediately.