Executive brief
WowOptin is a WordPress plugin used to create marketing popups and lead generation forms. A security flaw in the plugin allows unauthorized individuals to bypass intended access controls due to missing authorization checks. This could allow an attacker to modify settings or perform actions that should be restricted to site administrators, potentially disrupting marketing campaigns or site behavior.
Technical details
The WowOptin plugin for WordPress suffers from a broken access control vulnerability (CWE-862) due to missing authorization checks in certain functions. An unauthenticated remote attacker can exploit this flaw to execute actions or modify configurations that are intended to be restricted to higher-privileged users. The vulnerability stems from the plugin failing to validate the user's identity or permissions before processing specific requests. The issue affects versions up to and including 1.4.37 and is resolved in version 1.4.38.
Affected products
- WPXPO WowOptin <= 1.4.37
Timeline
- 2026-01-30: disclosed: Vulnerability reported by Nabil Irawan
- 2026-03-01: advisory: Patchstack published advisory and patch information
- 2026-04-08: disclosed: CVE published to NVD