LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-18322

Published
CVSS8.8
Severityhigh
WeaknessCWE-269
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing `save` from protected actions; this is compounded by the subscription confirmation email embedding the same generic `pps_nonce` that the unauthenticated `wp_ajax_nopriv_save` endpoint accepts, and by the complete absence of any server-side role allowlist in `createWpSubscriber()`. This makes it possible for unauthenticate

References

← Back to the CVE Tracker

Our coverage of CVE-2026-18322

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-18322.