CVE-2026-14603: WowOptin < 1.4.38 - Unauthenticated Opt-in Deactivation and Template Row Injection
The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: WowOptin: Next-Gen Popup Makerto a version that resolves this vulnerability.Fixed in 1.4.38 - Compensating control
After upgrading to a version at or above 1.4.38, ensure the plugin’s REST endpoint is protected so unauthenticated users cannot disable the site’s opt-in forms or inject new template-based opt-in rows.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14603?
CVE-2026-14603 has a high severity rating of 7.5 according to the CVSS 3.1 scoring system.
How do I fix CVE-2026-14603?
To fix CVE-2026-14603, you should update the WowOptin plugin to version 1.4.38 or later.
What impact does CVE-2026-14603 have on my website?
CVE-2026-14603 allows unauthenticated users to disable opt-in forms and inject new template rows into your database, posing a security risk.
What versions are affected by CVE-2026-14603?
CVE-2026-14603 affects all versions of the WowOptin plugin prior to 1.4.38.
Is user authentication required to exploit CVE-2026-14603?
No, exploitation of CVE-2026-14603 does not require user authentication, making it more dangerous.