← Vulnerability feed

Vulnerability record · CVE-2021-24275 · published 5 May 2021

CVE-2021-24275: Supsystic popup cross-site scripting vulnerability

Supsystic · Popup

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

6.1 CVSS 3.1 Medium EPSS 18% · top 2.9% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site Scripting issue

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24275 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-39997Supsystic popup missing authorization vulnerabilityMissing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This …EPSS 0.67%9.8CVE-2023-51353Supsystic popup missing authorization vulnerabilityMissing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Exploiting Incorrectly Configured Access Control Securi…EPSS 0.57%9.8CVE-2023-3186Supsystic popup vulnerabilityThe Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary prope…EPSS 1.5%9.1CVE-2024-52434Supsystic popup code injection vulnerabilityDeserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup …EPSS 1.1%8.8CVE-2016-10915Supsystic popup cross-site request forgery vulnerabilityThe popup-by-supsystic plugin before 1.7.9 for WordPress has CSRF.EPSS 0.68%6.5CVE-2023-46197Supsystic popup path traversal vulnerabilityImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in supsystic.Com Popup by Supsystic allows Relative Path…EPSS 1.3%5.3CVE-2022-0424Supsystic popup missing authentication for critical function vulnerabilityThe Popup by Supsystic WordPress plugin before 1.10.9 does not have any authentication and authorisation in an AJAX action, allowing unauthenticated …EPSS 3.0%4.3CVE-2024-31421Supsystic popup missing authorization vulnerabilityMissing Authorization vulnerability in supsystic Popup by Supsystic popup-by-supsystic.This issue affects Popup by Supsystic: from n/a through <= 1.1…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2021-24275), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.