External risk intelligence

Popup by Supsystic Unauthenticated Broken Authentication Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-73381

The vulnerability affects a WordPress plugin designed to create public-facing popups. Such plugins are typically deployed on web servers to interact directly with site visitors, making the affected functionality commonly reachable from the public internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a widely used WordPress plugin that allows for the creation of popups. This issue, related to authentication, could allow unauthorized access and modification of systems without requiring any login credentials. The main concern at this time is to determine if our organization utilizes this specific plugin and, if so, to understand the potential exposure.

  • Unauthenticated users can bypass login controls.
  • Affects a common tool for website engagement.
  • Confirm relevance and assess exposure to this plugin.

Attack Path

How an attacker could exploit the issue

An attacker can reach an unauthenticated broken authentication vulnerability in the Popup by Supsystic plugin. This vulnerability is accessible over the network and does not require any privileges or user interaction to trigger. Successful exploitation could lead to an attacker gaining unauthorized access and making modifications to the affected system.

  • Accessible via the network.
  • Triggered by directly interacting with the plugin.
  • Leads to unauthorized access.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in Popup by Supsystic could allow an unauthenticated attacker to manipulate service behavior when the plugin is used to display popups. It does not appear to expose system or user data.

  • Service behavior manipulation.
  • Unauthenticated network access.
  • Disruption of website functionality.

Operational Fix

Recommended remediation, mitigation, and detection steps

This unauthenticated broken authentication vulnerability in a WordPress plugin likely affects website owners and their web administrators. The first step is to identify all instances of this plugin, determine if they are internet-reachable and business-critical, and then assign ownership for remediation.

  • Website owners should own the issue.
  • Verify plugin reachability and business impact.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Popup by Supsystic plugin?

Popup by Supsystic is a WordPress plugin used to build and manage website popups, such as subscription forms, contact boxes, and promotional banners. It functions as an add-on to WordPress sites, helping administrators engage visitors directly through UI elements that appear while users browse the web.

What does broken authentication mean for CVE-2026-73381?

This vulnerability is classified as CWE-288, which involves improper authentication. In the context of CVE-2026-73381, the plugin fails to verify the identity of someone trying to access its administrative functions. Essentially, the software acts as if a visitor has valid credentials, allowing them to perform actions reserved for authorized users.

How can an attacker trigger this vulnerability?

An attacker triggers this by interacting with the plugin over the network without needing any login or special user privileges. It is important to note that this does not require a user to click on a link or perform any prior interaction. Simply accessing the network path used by the plugin is enough to bypass the authentication check.

Why should I be concerned about this vulnerability?

Halo Surface Signal indicates this plugin is designed for public-facing website engagement, meaning the affected components are typically reachable from the internet. Because it resides on web servers meant for public access, any instance of this plugin on your site is likely exposed to remote, unauthenticated attempts to modify service behavior.

Do I need to take immediate action if I use this plugin?

Yes. Start by auditing your WordPress environment to confirm if this specific plugin is installed. Once identified, prioritize these instances based on their business criticality. Coordinate with your website administrators to restrict access or apply the necessary updates to ensure authentication controls are correctly enforced.

References