PT-2023-23493 · WordPress · The Popup By Supsystic

Drwtsn

·

Published

2023-07-17

·

Updated

2023-07-28

·

CVE-2023-3186

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The Popup by Supsystic WordPress plugin versions prior to 1.10.19
Description The issue allows an attacker to inject arbitrary properties into Object.prototype due to a prototype pollution vulnerability.
Recommendations For versions prior to 1.10.19, update to version 1.10.19 or later to resolve the issue.

Exploit

Fix

Related Identifiers

CVE-2023-3186

Affected Products

The Popup By Supsystic