PT-2026-67946 · Supsystystic · Smart Popup

·

CVE-2026-18322

·

Published

2026-08-05

·

Updated

2026-08-05

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Smart Popup by Supsystystic versions prior to 1.12.1
Description A privilege escalation issue exists due to a permission map collision in the havePermissions() function within classes/frame.php. The use of array merge() overwrites the administrator-restricted method list, removing save from protected actions. This is further exacerbated by the wp ajax nopriv save endpoint accepting a generic pps nonce found in subscription confirmation emails and the lack of a server-side role allowlist in the createWpSubscriber() function. An unauthenticated attacker can send a crafted POST request to the admin-ajax.php endpoint, utilizing the pps nonce and setting the params[tpl][sub wp create user role] variable to administrator via the popupControllerPps::save() action to create a WordPress Administrator account.
Recommendations Update Smart Popup by Supsystystic to a version newer than 1.12.0. As a temporary mitigation, restrict access to the admin-ajax.php endpoint or disable the popupControllerPps::save() action if possible.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18322

Affected Products

Smart Popup