Smart Popup by Supsystic <= 1.12.0 - Unauthenticated Privilege Escalation to Administrator
Description
The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the havePermissions() function in classes/frame.php, where array_merge() overwrites the popup module's administrator-restricted method list with the base controller's value, silently removing save from protected actions; this is compounded by the subscription confirmation email embedding the same generic pps_nonce that the unauthenticated wp_ajax_nopriv_save endpoint accepts, and by the complete absence of any server-side role allowlist in createWpSubscriber(). This makes it possible for unauthenticated attackers to submit a crafted POST request to admin-ajax.php using a nonce obtained from a public subscription confirmation email, setting params[tpl][sub_wp_create_user_role] to administrator via the exposed popupControllerPps::save() action, and then triggering the stored confirmation flow to create a persistent WordPress Administrator account with attacker-chosen credentials.
Affected products
1- Range: <=1.12.0
Patches
Vulnerability mechanics
References
7- plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/classes/frame.phpmitre
- plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/popup/models/popup.phpmitre
- plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.phpmitre
- plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.phpmitre
- plugins.trac.wordpress.org/browser/popup-by-supsystic/tags/1.11.2/modules/subscribe/models/subscribe.phpmitre
- plugins.trac.wordpress.org/changesetmitre
- www.wordfence.com/threat-intel/vulnerabilities/id/835579b0-8a96-40fa-a6a3-30571a0a1d0amitre
News mentions
0No linked articles in our index yet.