Extension WordPress
Vulnérabilités WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation
Cette page rassemble les failles publiées pour WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation
3 fiches
WowOptin: Next-Gen Popup Maker <= 1.4.29 – Unauthenticated Server-Side Request Forgery via 'link' Parameter in REST API
The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a…
*-1.4.29
1.4.30
20/03/2026
WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation <= 1.4.24 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation
The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up…
*-1.4.24
1.4.25
04/03/2026
WowOptin <= 1.4.37 – Missing Authorization
The WowOptin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 1.4.37. This makes it possible for unauthenticated attackers to perform an unauthorized action.
*-1.4.37
1.4.38
01/03/2026
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.