PT-2026-64244 · WordPress · Wowoptin: Next-Gen Popup Maker
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WowOptin: Next-Gen Popup Maker versions prior to 1.4.38
Description
Insufficient authorization on a REST endpoint allows unauthenticated users to disable all opt-in forms on the site and insert new template-based opt-in rows into the database.
Recommendations
Update WowOptin: Next-Gen Popup Maker to version 1.4.38 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wowoptin: Next-Gen Popup Maker