Description
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.
Published: 2026-07-24
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WowOptin: Next‑Gen Popup Maker plugin contains a REST endpoint that can be called without any authentication. Attacks through this interface allow an unauthenticated user to disable all opt‑in forms on a WordPress site and to create new template‑based opt‑in rows directly in the database. This flaw, a classic authorization omission identified as CWE‑284, delivers both an availability impact by disabling marketing mechanisms and a data‑integrity impact by injecting unwanted entries into the database.

Affected Systems

Any WordPress installation that runs WowOptin: Next‑Gen Popup Maker version earlier than 1.4.38 is affected. Site administrators who have not applied the 1.4.38 release or a later patch may experience complete opt‑in deactivation and the presence of unauthorized rows within the database tables associated with the plugin.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating moderate‑to‑high risk. The EPSS score is reported as less than 1 %, showing that exploitation attempts are currently rare, and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a web request to the vulnerable REST endpoint, which requires no credentials. Although the probability of exploitation is low at present, the potential damage—disabling marketing forms and compromising database integrity—demands timely mitigation.

Generated by OpenCVE AI on August 3, 2026 at 20:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update WowOptin to version 1.4.38 or later.
  • If an update cannot be applied immediately, filter the /wp-json/wowoptin/v1/ REST endpoint so that only authenticated administrators can access it, using a security plugin or web‑application firewall.
  • Inspect the plugin’s database tables for any unauthorized opt‑in rows and delete them; consider restoring the site from a clean backup if the data integrity is compromised.

Generated by OpenCVE AI on August 3, 2026 at 20:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wowoptin
Wowoptin next-gen Popup Maker
Vendors & Products Wordpress
Wordpress wordpress
Wowoptin
Wowoptin next-gen Popup Maker

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 24 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Description The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.
Title WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection
References

Subscriptions

Wordpress Wordpress
Wowoptin Next-gen Popup Maker
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-24T19:39:48.699Z

Reserved: 2026-07-03T12:59:52.015Z

Link: CVE-2026-14603

cve-icon Vulnrichment

Updated: 2026-07-24T19:39:42.584Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T07:16:33.120

Modified: 2026-07-24T20:48:39.923

Link: CVE-2026-14603

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:45:03Z

Weaknesses