← WordPress Vulnerabilities
WordPress security by component

WowOptin

WowOptin is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jul 24, 2026; the highest CVE/CNA score is 8.8.

Plugin slug: optin

CVE-2026-14603: WowOptin public recipe route can disable every opt-in

WowOptin before 1.4.38 exposes GET /wp-json/optn/v1/recipes/ with permission_callback set to __return_true. The unauthenticated request's disable_others and status values reach handle_activate_recipe() and Db::activate_recipe(), allowing an attacker to disable every existing opt-in form and insert an enabled vendor-template row into the database.

PublishedJul 24, 2026
Known safe version1.4.38
Safe version
Jul 24, 2026 CVE-2026-14603
WowOptin public recipe route can disable every opt-in
WowOptin before 1.4.38 exposes GET /wp-json/optn/v1/recipes/ with permission_callback set to __return_true. The unauthenticated request's disable_others and status values reach handle_activate_recipe() and Db::activate_recipe(), allowing an attacker to disable every existing opt-in form and insert an enabled vendor-template row into the database.
1.4.38
CVE6.5
NVDPending
Apr 08, 2026 CVE-2026-39700
WowOptin: A security weakness
WowOptin is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.4.32.
> 1.4.32
CVE5.3
NVDPending
Mar 21, 2026 CVE-2026-4302
WowOptin: Next-Gen Popup Maker: Server-side request forgery
WowOptin: Next-Gen Popup Maker is affected by server-side request forgery. The vulnerable path is reachable without authentication. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE7.2
NVDPending
Mar 05, 2026 CVE-2026-1720
WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation: A security weakness
WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation is affected by a security weakness. Exploitation requires at least subscriber-level access. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE8.8
NVDPending