WP Optin Wheel <= 1.4.7 - Authenticated (Admin+) Server-Side Request Forgery
medium
The WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arb...
- CVSS:
- 5.5
- Affected:
- up to 1.4.7
- Fixed in:
- 1.4.8
- Disclosed:
- Apr 1, 2025
CVE-2025-31824 on NVD →
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.4.8
unknown
[en] Server-Side Request Forgery (SSRF) vulnerability in Wombat Plugins WP Optin Wheel allows Server Side Request Forgery.
This issue affects WP Optin Wheel: from n/a through 1.4.7.
- Affected:
- up to 1.4.8
- Fixed in:
- 1.4.8
- Disclosed:
- Apr 1, 2025
CVE-2025-31824 on NVD →
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.4.4
unknown
[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue affects WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce: from n/a through 1.4.3.
- Affected:
- up to 1.4.4
- Fixed in:
- 1.4.4
- Disclosed:
- Jan 8, 2024
CVE-2023-51408 on NVD →
WP Optin Wheel <= 1.4.2 - Sensitive Information Exposure via Log File
medium
The WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the plugin's debug log file. This makes it possible for unauthenticated attackers to extract sensitive data includin...
- CVSS:
- 5.3
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Dec 27, 2023
CVE-2023-51408 on NVD →
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.3.5
unknown
Information Disclosure vulnerability (Mailchimp lists, logs) discovered in WordPress WP Optin Wheel plugin (versions <= 1.3.4).
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Jan 16, 2022
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.3.5
unknown
Subscribe+ Plugin Options Update (Toggle Wheel status, Update wheels) vulnerability discovered in WordPress WP Optin Wheel plugin (versions <= 1.3.4).
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Jan 16, 2022
WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.3.5
unknown
Subscriber+ Arbitrary Delete Wheels or Posts vulnerability discovered in WordPress WP Optin Wheel plugin (versions <= 1.3.4).
- Affected:
- up to 1.3.5
- Fixed in:
- 1.3.5
- Disclosed:
- Jan 16, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database