plugin

Wp Optin Wheel Vulnerabilities

7 known security issues reported for the Wp Optin Wheel WordPress plugin. Most recent disclosed Apr 1, 2025.

2 medium

Running Wp Optin Wheel on your site? Check whether your installed version is affected.

Scan your site free

WP Optin Wheel <= 1.4.7 - Authenticated (Admin+) Server-Side Request Forgery

medium

The WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.7. This makes it possible for authenticated attackers, with Administrator-level access and above, to make web requests to arb...

CVSS:
5.5
Affected:
up to 1.4.7
Fixed in:
1.4.8
Disclosed:
Apr 1, 2025

CVE-2025-31824 on NVD →

WP Optin Wheel &#8211; Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.4.8

unknown

[en] Server-Side Request Forgery (SSRF) vulnerability in Wombat Plugins WP Optin Wheel allows Server Side Request Forgery. This issue affects WP Optin Wheel: from n/a through 1.4.7.

Affected:
up to 1.4.8
Fixed in:
1.4.8
Disclosed:
Apr 1, 2025

CVE-2025-31824 on NVD →

WP Optin Wheel &#8211; Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.4.4

unknown

[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in StudioWombat WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce.This issue affects WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce: from n/a through 1.4.3.

Affected:
up to 1.4.4
Fixed in:
1.4.4
Disclosed:
Jan 8, 2024

CVE-2023-51408 on NVD →

WP Optin Wheel <= 1.4.2 - Sensitive Information Exposure via Log File

medium

The WP Optin Wheel – Gamified Optin Email Marketing Tool for WordPress and WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.2 via the plugin's debug log file. This makes it possible for unauthenticated attackers to extract sensitive data includin...

CVSS:
5.3
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Dec 27, 2023

CVE-2023-51408 on NVD →

WP Optin Wheel &#8211; Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.3.5

unknown

Information Disclosure vulnerability (Mailchimp lists, logs) discovered in WordPress WP Optin Wheel plugin (versions <= 1.3.4).

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Jan 16, 2022

WP Optin Wheel &#8211; Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.3.5

unknown

Subscribe+ Plugin Options Update (Toggle Wheel status, Update wheels) vulnerability discovered in WordPress WP Optin Wheel plugin (versions <= 1.3.4).

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Jan 16, 2022

WP Optin Wheel &#8211; Gamified Optin Email Marketing Tool for WordPress and WooCommerce [wp-optin-wheel] < 1.3.5

unknown

Subscriber+ Arbitrary Delete Wheels or Posts vulnerability discovered in WordPress WP Optin Wheel plugin (versions <= 1.3.4).

Affected:
up to 1.3.5
Fixed in:
1.3.5
Disclosed:
Jan 16, 2022

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database