VYPR

Smart Popup by Supsystic

by WordPress

CVEs (1)

  • CVE-2026-18322HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites the popup…