What is CVE-2026-14603?
The WowOptin: Next-Gen Popup Maker WordPress plugin lacks proper authorization on a REST endpoint (CVE-2026-14603). This vulnerability allows unauthenticated users to disable all site opt-in forms and insert new template-based opt-in rows into the database. Versions before 1.4.38 are affected and should be updated immediately.
Azərbaycanca: WowOptin: Next-Gen Popup Maker WordPress plaginində REST endpoint üzərində düzgün avtorizasiya yoxdur (CVE-2026-14603). Bu boşluq autentifikasiya olunmamış şəxslərə saytdakı bütün opt-in formalarını söndürməyə və verilənlər bazasına yeni şablon əsaslı opt-in sətirləri əlavə etməyə imkan verir. Plaginin 1.4.38 versiyasından əvvəlki versiyaları təsirlənir, dərhal yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What actions can an unauthenticated user perform using the CVE-2026-14603 vulnerability?
An unauthenticated user can disable all site opt-in forms and insert new template-based opt-in rows into the database.
In which version of the WowOptin plugin is CVE-2026-14603 fixed?
Versions before 1.4.38 are affected, so the plugin should be updated to at least version 1.4.38.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.