Back to overview

CVE-2026-14603

Description
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.

Metadata

CVE ID
CVE-2026-14603
State
PUBLISHED
Assigner
WPScan
Reserved
2026-07-03 12:59 UTC
Published
2026-07-24 06:00 UTC
Last updated
2026-07-24 06:00 UTC
Vendor / Product
Unknown / WowOptin: Next-Gen Popup Maker
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown WowOptin: Next-Gen Popup Maker 0 < 1.4.38
Weakness (CWE)
CWESourceDescription
cna CWE-284 Improper Access Control
Back to overview