WowOptin <= 1.4.37 - Missing Authorization to Unauthenticated Opt-In Deactivation
medium
The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.4.37. This makes it possible for unauthenticated attackers to deactivate opt-in sta...
- CVSS:
- 5.3
- Affected:
- up to 1.4.37
- Fixed in:
- 1.4.38
- Disclosed:
- Jul 3, 2026
CVE-2026-14603 on NVD →
WowOptin: Next-Gen Popup Maker <= 1.4.29 - Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API
high
The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a permission_callback of __return_true that passes user-supplied...
- CVSS:
- 7.2
- Affected:
- up to 1.4.29
- Fixed in:
- 1.4.30
- Disclosed:
- Mar 20, 2026
CVE-2026-4302 on NVD →
WowOptin - WordPress WowOptin: Next-Gen Popup Maker - Create Stunning Popups and Optins for Lead Generation plugin <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary plugin Installation vulnerability
high
WordPress WowOptin: Next-Gen Popup Maker - Create Stunning Popups and Optins for Lead Generation plugin <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary plugin Installation vulnerability
- CVSS:
- 8.8
- Affected:
- up to 1.4.24
- Fixed in:
- 1.4.25
- Disclosed:
- Mar 6, 2026
WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
high
The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up to, and including, 1.4.24. This makes it possible f...
- CVSS:
- 8.8
- Affected:
- up to 1.4.24
- Fixed in:
- 1.4.25
- Disclosed:
- Mar 4, 2026
CVE-2026-1720 on NVD →
WowOptin <= 1.4.37 - Missing Authorization
medium
The WowOptin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.37. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 1.4.37
- Fixed in:
- 1.4.38
- Disclosed:
- Mar 1, 2026
CVE-2026-39700 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database