Privilege Escalation Vulnerability in Smart Popup Plugin by Supsystic
CVE-2026-18322
8.8HIGH
What is CVE-2026-18322?
The Smart Popup plugin by Supsystic for WordPress has a vulnerability that allows unauthenticated attackers to escalate privileges to that of an administrator. This occurs due to a flaw in how permissions are handled, specifically in the havePermissions() function. A poorly designed permission mapping allows the overwrite of crucial actions, resulting in unauthorized access to protected areas of the plugin. Attackers can exploit this vulnerability to submit a crafted POST request using a nonce acquired from a public email confirmation, leading to the creation of a persistent WordPress Administrator account with arbitrary credentials.
Affected Version(s)
Smart Popup by Supsystic 0 <= 1.12.0