S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24275 Scanner

CVE-2021-24275 scanner - Cross-Site Scripting (XSS) vulnerability in Popup by Supsystic plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.4k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24275
6.1
CVSS

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Popup by Supsysticby Supsystic
AFFECTED< 1.10.5SAFE ✓≥ 1.10.5
Updated Aug 21, 2026View on NVD →
Detail

The Popup by Supsystic plugin for WordPress is a tool used to create pop-up windows that appear on a website. It offers a range of customization options, including the ability to choose from various templates and create custom designs with a drag-and-drop interface. The pop-ups can be triggered by different events, such as time spent on a page or clicked links, and can be used for various purposes, such as lead generation or advertising.

Recently, a vulnerability has been detected in this plugin, identified as CVE-2021-24275. This vulnerability occurs due to the plugin's failure to sanitize the tab parameter of its options page before using it for an attribute, which can lead to a reflected cross-site scripting (XSS) attack. This means an attacker could inject malicious code into the website, which would then be executed by unsuspecting users who interact with the pop-up.

If exploited, this vulnerability can have serious consequences for website owners and users alike. Attackers could use XSS attacks to steal sensitive information, such as login credentials or credit card details, or to distribute malware. They could also deface the website or shut it down entirely, causing a loss of revenue and reputation.

At s4e.io, we offer pro features that allow users to easily and quickly learn about vulnerabilities in their digital assets. With our platform, you can stay informed about the latest threats and protect your website from attackers. Don't let your website be vulnerable to XSS attacks - try s4e.io today!

 

REFERENCES

Solution Advice

To protect against this vulnerability, website owners using the Popup by Supsystic plugin should take the following precautions:

  • Update to the latest version of the plugin, which includes a fix for the vulnerability.
  • Use a web application firewall (WAF) to detect and block attacks targeting this vulnerability.
  • Sanitize user input by using input validation, output encoding, and proper escape characters.
  • Limit user privileges and restrict input to only the necessary fields.
  • Stay aware of the latest security threats and take action to prevent them.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.