Supsystic Popup Plugin cross-site request forgery
Published Jun 20, 2022
4.3
MEDIUMCVSS 3.1
EPSS 0.71%
Description
A vulnerability was found in Supsystic Popup Plugin 1.7.6 and classified as problematic. This issue affects some unknown processing. The manipulation leads to cross-site request forgery. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected products
-
- Version 1.7.6StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Supsystic | Popup Plugin | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 14, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (18 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.71% (0.00713) | 51.93th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.58% (0.00580) | 42.94th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.10% (0.00098) | 24.55th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.27% (0.01275) | 67.11th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.10% (0.00098) | 25.10th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.18% (0.00178) | 56.34th | v3 (v2023.03.01) |
| Jan 26, 2024 | 0.16% (0.00156) | 51.91th | v3 (v2023.03.01) |
| Jan 11, 2024 | 0.15% (0.00150) | 50.99th | v3 (v2023.03.01) |
| Dec 1, 2023 | 0.16% (0.00161) | 52.55th | v3 (v2023.03.01) |
| Jun 27, 2023 | 0.13% (0.00134) | 47.38th | v3 (v2023.03.01) |
| May 21, 2023 | 0.07% (0.00068) | 27.72th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.06% (0.00056) | 21.37th | v3 (v2023.03.01) |
| Mar 6, 2023 | 8.38% (0.08382) | 93.89th | v2 (v2022.01.01) |
| Nov 15, 2022 | 8.38% (0.08382) | 93.72th | v2 (v2022.01.01) |
| Jul 15, 2022 | 1.02% (0.01018) | 38.29th | v2 (v2022.01.01) |
| Jun 29, 2022 | 8.38% (0.08382) | 93.51th | v2 (v2022.01.01) |
| Jun 22, 2022 | 6.09% (0.06089) | 89.91th | v2 (v2022.01.01) |
| Jun 21, 2022 | 0.95% (0.00950) | 29.65th | v2 (v2022.01.01) |
References (4)
- http://seclists.org/fulldisclosure/2017/Feb/97 x_refsource_MISCMailing ListThird Party Advisory
- https://map.httpcs.com/alert/284665 x_refsource_MISCThird Party Advisory
- https://vuldb.com/?id.97385 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/41485/ x_refsource_MISCExploitThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| http://seclists.org/fulldisclosure/2017/Feb/97 | x_refsource_MISCMailing ListThird Party Advisory | |
| https://map.httpcs.com/alert/284665 | x_refsource_MISCThird Party Advisory | |
| https://vuldb.com/?id.97385 | x_refsource_MISCThird Party AdvisoryVDB Entry | |
| https://www.exploit-db.com/exploits/41485/ | x_refsource_MISCExploitThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.