Supsystic develops a small portfolio of WordPress plugins focused on user engagement, data capture, and content enhancement—popup builders, maps, social sharing, contact forms, and data tables—that collectively serve a significant presence across WordPress deployments. Vulnerabilities affecting these plugins skew toward moderate severity and have a recurring character centered on web-application input and authorization flaws: CSRF, cross-site scripting, missing or incorrect authorization controls, and code injection weaknesses that are endemic to plugin ecosystems where developers operate with varied security maturity. The exposure pattern reflects the plugins' direct exposure to both authenticated admin interfaces and public-facing user input, making them a persistent target for account compromise, privilege escalation, and website defacement. Defenders running these plugins should prioritize timely updates and consider restricting plugin modification to trusted administrators; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Supsystic over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-24275MEDIUM The Popup by Supsystic WordPress plugin before 1.10.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cross-Site | May 5, 2021 | 6.1 | 47 | NO | YES |
CVE-2021-24274MEDIUM The Ultimate Maps by Supsystic WordPress plugin before 1.2.5 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cro | May 5, 2021 | 6.1 | 47 | NO | YES |
CVE-2021-24276MEDIUM The Contact Form by Supsystic WordPress plugin before 1.7.15 did not sanitise the tab parameter of its options page before outputting it in an attribute, leading to a reflected Cro | May 5, 2021 | 6.1 | 46 | NO | YES |
CVE-2023-3186CRITICAL The Popup by Supsystic WordPress plugin before 1.10.19 has a prototype pollution vulnerability that could allow an attacker to inject arbitrary properties into Object.prototype. | Jul 17, 2023 | 9.8 | 30 | NO | NO |
CVE-2023-39997CRITICAL Missing Authorization vulnerability in supsystic.com Popup by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Popup by Supsysti | Dec 13, 2024 | 9.8 | 28 | NO | NO |
CVE-2022-47155HIGH Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Slider by Supsystic plugin <= 1.8.5 versions. | Mar 14, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-27235HIGH Multiple Broken Access Control vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress. | Jul 22, 2022 | 8.8 | 27 | NO | NO |
CVE-2023-33926HIGH Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps plugin <= 1.11.7 versions. | May 28, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-22714HIGH Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Coming Soon by Supsystic plugin <= 1.7.10 versions. | May 22, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-2528HIGH The Contact Form by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.24. This is due to missing or incorrect nonce v | May 17, 2023 | 8.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Supsystic.
Media articles that mention a CVE ID that affects a product developed by Supsystic — matched by CVE ID, not by vendor name.