SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-14603

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The WowOptin: Next-Gen Popup Maker plugin for WordPress prior to version 1.4.38 is vulnerable due to inadequate authorization on a REST endpoint, enabling unauthenticated users to disable all opt-in forms and manipulate the database by inserting new template-based opt-in entries. This could lead to significant disruption of marketing efforts and potential data integrity issues. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-14603
Severity
HIGH
CVSS
7.5
EPSS
0.24%
WordPress

Original NVD Description

The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.