Impact
The WowOptin: Next‑Gen Popup Maker plugin contains a REST endpoint that can be called without any authentication. Attacks through this interface allow an unauthenticated user to disable all opt‑in forms on a WordPress site and to create new template‑based opt‑in rows directly in the database. This flaw, a classic authorization omission identified as CWE‑284, delivers both an availability impact by disabling marketing mechanisms and a data‑integrity impact by injecting unwanted entries into the database.
Affected Systems
Any WordPress installation that runs WowOptin: Next‑Gen Popup Maker version earlier than 1.4.38 is affected. Site administrators who have not applied the 1.4.38 release or a later patch may experience complete opt‑in deactivation and the presence of unauthorized rows within the database tables associated with the plugin.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating moderate‑to‑high risk. The EPSS score is reported as less than 1 %, showing that exploitation attempts are currently rare, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a web request to the vulnerable REST endpoint, which requires no credentials. Although the probability of exploitation is low at present, the potential damage—disabling marketing forms and compromising database integrity—demands timely mitigation.
OpenCVE Enrichment