What is CVE-2026-18322?
CVE-2026-18322 is a privilege escalation vulnerability in the Smart Popup by Supsystic plugin for WordPress, affecting versions up to 1.12.0. It stems from a permission map collision in the `havePermissions()` function in `classes/frame.php`, where `array_merge()` overwrites admin-level permissions. Users should update to the latest patched version immediately.
Azərbaycanca: CVE-2026-18322 WordPress üçün Smart Popup by Supsystic plaginin 1.12.0 və əvvəlki versiyalarında privilege escalation boşluğudur. `classes/frame.php` faylındakı `havePermissions()` funksiyasında `array_merge()` istifadəsi səbəbindən permissions map collision baş verir və bu, istifadəçilərə daha yüksək səviyyəli icazələr əldə etməyə imkan verir. Plagin ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
Which versions of the Smart Popup by Supsystic plugin are affected by CVE-2026-18322?
This vulnerability affects plugin versions up to and including 1.12.0.
What is the root cause of CVE-2026-18322?
The vulnerability is caused by a permission map collision in the `havePermissions()` function within the `classes/frame.php` file due to the use of `array_merge()`.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.