CVE-2023-3186: Supsystic Popup

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype.

Affected products

  • Supsystic Popup: before 1.10.19 (fixed in 1.10.19)

Published 2023-07-17. Last modified 2026-06-17.