CVE-2026-14603 PUBLISHED

WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection

Assigner: WPScan
Reserved: 03.07.2026 Published: 24.07.2026 Updated: 24.07.2026

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

Product Status

Vendor Unknown
Product WowOptin: Next-Gen Popup Maker
Versions Default: unaffected
  • affected from 0 to 1.4.38 (excl.)

Credits

  • Pedro Pinho finder
  • WPScan coordinator

References

Problem Types

  • CWE-284 Improper Access Control CWE