Executive brief
A vulnerability in the WowOptin WordPress plugin allows unauthorized individuals to remotely disable all active marketing popups and opt-in forms on a website. Attackers can also inject new, unauthorized forms from the plugin's template library into the site's database. This can disrupt lead generation efforts, damage brand reputation by displaying unexpected content, and interfere with normal site operations.
Technical details
The WowOptin plugin fails to implement authorization checks on the 'GET /wp-json/optn/v1/recipes/<id>' REST endpoint due to a permission_callback set to '__return_true'. An unauthenticated attacker can send a crafted request to this endpoint with specific query parameters, such as 'disable_others=1', which triggers an unconditional database UPDATE to disable all existing opt-in forms. Additionally, the 'activate_recipe' function allows the injection of new opt-in rows from the vendor's template API into the local database. This vulnerability allows for unauthorized modification of site content and disruption of service without any user interaction or authentication. The issue is resolved in version 1.4.38 by implementing proper capability checks.
Affected products
- WowOptin WowOptin: Next-Gen Popup Maker < 1.4.38
Timeline
- 2026-07-03: disclosed: Publicly published by WPScan
- 2026-07-24: advisory: NVD publication date
- 2026-07-24: patched: Fixed in version 1.4.38