PT-2026-67946 · Supsystystic · Smart Popup
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Smart Popup by Supsystystic versions prior to 1.12.1
Description
A privilege escalation issue exists due to a permission map collision in the
havePermissions() function within classes/frame.php. The use of array merge() overwrites the administrator-restricted method list, removing save from protected actions. This is further exacerbated by the wp ajax nopriv save endpoint accepting a generic pps nonce found in subscription confirmation emails and the lack of a server-side role allowlist in the createWpSubscriber() function. An unauthenticated attacker can send a crafted POST request to the admin-ajax.php endpoint, utilizing the pps nonce and setting the params[tpl][sub wp create user role] variable to administrator via the popupControllerPps::save() action to create a WordPress Administrator account.Recommendations
Update Smart Popup by Supsystystic to a version newer than 1.12.0.
As a temporary mitigation, restrict access to the
admin-ajax.php endpoint or disable the popupControllerPps::save() action if possible.Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Smart Popup