{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/smart-popup-by-supsystic/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-18322"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Smart Popup by Supsystic"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Supsystic"],"content_html":"\u003cp\u003eThe Smart Popup by Supsystic plugin for WordPress (versions up to and including 1.12.0) contains a critical privilege escalation vulnerability. The issue stems from a permission map collision in the \u003ccode\u003ehavePermissions()\u003c/code\u003e function within \u003ccode\u003eclasses/frame.php\u003c/code\u003e. Specifically, an \u003ccode\u003earray_merge()\u003c/code\u003e operation inadvertently overwrites restricted method lists, causing the \u003ccode\u003esave\u003c/code\u003e action to lose its administrator-only protection.\u003c/p\u003e\n\u003cp\u003eThis flaw is further exacerbated by the plugin using a generic \u003ccode\u003epps_nonce\u003c/code\u003e for subscription confirmation emails that is also accepted by the unauthenticated \u003ccode\u003ewp_ajax_nopriv_save\u003c/code\u003e endpoint. Because the \u003ccode\u003ecreateWpSubscriber()\u003c/code\u003e function lacks any server-side role allowlist, an attacker can submit a crafted POST request to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e. By manipulating the \u003ccode\u003eparams[tpl][sub_wp_create_user_role]\u003c/code\u003e parameter, an attacker can elevate their privileges during the account creation process to become a WordPress Administrator. This vulnerability allows for full site takeover by unauthenticated parties.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site running a vulnerable version of the Smart Popup by Supsystic plugin.\u003c/li\u003e\n\u003cli\u003eAttacker triggers a subscription confirmation flow on the public-facing site to receive a confirmation email.\u003c/li\u003e\n\u003cli\u003eAttacker extracts the static \u003ccode\u003epps_nonce\u003c/code\u003e from the publicly accessible subscription confirmation link in the email.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious POST request to \u003ccode\u003ewp-admin/admin-ajax.php\u003c/code\u003e targeting the \u003ccode\u003ewp_ajax_nopriv_save\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the harvested \u003ccode\u003epps_nonce\u003c/code\u003e in the request to bypass initial validation.\u003c/li\u003e\n\u003cli\u003eAttacker injects \u003ccode\u003eparams[tpl][sub_wp_create_user_role]=administrator\u003c/code\u003e into the POST body.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003epopupControllerPps::save()\u003c/code\u003e method executes and processes the creation of a new subscriber account.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003ecreateWpSubscriber()\u003c/code\u003e function processes the request without role validation, resulting in the creation of a new Administrator account.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full unauthorized administrative access to the affected WordPress installation. Attackers can gain control over the site, modify content, install malicious plugins, or exfiltrate sensitive data. All versions up to 1.12.0 are affected, posing a significant risk to any site utilizing this plugin for subscription management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Smart Popup by Supsystic plugin to the latest available version immediately to remediate CVE-2026-18322.\u003c/li\u003e\n\u003cli\u003eMonitor \u003ccode\u003eadmin-ajax.php\u003c/code\u003e requests for suspicious \u003ccode\u003eaction\u003c/code\u003e parameter values associated with \u003ccode\u003epopupControllerPps\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eImplement WAF rules to block or inspect POST requests to \u003ccode\u003eadmin-ajax.php\u003c/code\u003e containing unauthorized modifications to user role parameters.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts for suspicious additions, particularly those with administrative privileges created during unexpected timeframes.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-05T08:06:24Z","date_published":"2026-08-05T08:06:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18322/","summary":"An unauthenticated privilege escalation vulnerability (CVE-2026-18322) in the Smart Popup by Supsystic WordPress plugin allows remote attackers to create administrator accounts by exploiting improper permission checks and nonce reuse.","title":"Privilege Escalation in Smart Popup by Supsystic","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-18322/"}],"language":"en","title":"CraftedSignal Threat Feed - Smart Popup by Supsystic","version":"https://jsonfeed.org/version/1.1"}