๐Ÿ” CVE Alert

CVE-2026-18322

HIGH 8.8

Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials.

CWE CWE-269
Vendor supsysticcom
Product smart popup by supsystic
Published Aug 5, 2026
Stay Ahead of the Next One

Get instant alerts for supsysticcom smart popup by supsystic

Be the first to know when new high vulnerabilities affecting supsysticcom smart popup by supsystic are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

supsysticcom / Smart Popup by Supsystic
0 โ‰ค 1.12.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/835579b0-8a96-40fa-a6a3-30571a0a1d0a?source=cve plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/classes/frame.php#L180 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L440 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L292 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/popup/models/popup.php#L316 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.php#L358 plugins.trac.wordpress.org: https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3629986%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&old=3628131%40popup-by-supsystic%2Ftrunk%2Fmodules%2Fsubscribe%2Fmodels%2Fsubscribe.php&sfp_email=&sfph_mail=

Credits

daroo