VYPR

Smart Popup by Supsystic

by WordPress

CVEs (1)

  • CVE-2026-18322Aug 5, 2026
    risk 0.00cvss epss 0.00

    The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup…