CVE-2026-18322 HIGH

CVE-2026-18322: Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator

Vendor Supsysticcom
Product Smart Popup by Supsystic
Weakness CWE-269
Published August 5, 2026
Last update August 5, 2026

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticated attackers to submit a crafted POST request to `admin-ajax.php` using a nonce obtained from a public subscription confirmation email, setting `params[tpl][sub_wp_create_user_role]` to `administrator` via the exposed `popupControllerPps::save()` action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials.

Explanation of Vulnerability in Simple Terms

02Summary

Smart Popup by Supsystic versions 1.12.0 and earlier contain a privilege management flaw that allows authenticated users with low-level access to read sensitive data, modify site content, and disrupt service. An attacker needs only a standard user account and network access to exploit this vulnerability. Site administrators should update immediately to a version newer than 1.12.0.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify content, and disrupt the site's availability with a low-privilege user account.

Potential impact on your site

04Site Impact

Unauthorized users can access confidential information, alter site content, and cause service disruptions.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege user account on the site; no user interaction required.

Key dates

06Disclosure timeline

August 5, 2026 CVE published

Related vulnerabilities

08Related CVE