Product
An unauthenticated privilege escalation vulnerability (CVE-2026-18322) in the Smart Popup by Supsystic WordPress plugin allows remote attackers to create administrator accounts by exploiting improper permission checks and nonce reuse.