CVE-2026-1720Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the 'install_and_active_plugin' function in all versions up to, and including, 1.4.24. This makes it possible for authenticated attackers, with Subscriber-level access and above, to install and activate arbitrary plugins.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-05: 4Technical Details · 2026-03-05: 403-05
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets5 URLs
Full discourse4 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1720 WordPress WowOptin Plugin Unauthorized Plugin Installation Vulnera... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1720 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet points to CVE-2026-1720 affecting the WordPress WowOptin Plugin and links to a vulnerability details page, but it does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    0000035
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1720: HIGH] WordPress plugin WowOptin: Next-Gen Popup Maker has a security vulnerability in versions up to 1.4.24. Attackers with limited access can install unauthorized plugins.#cve,CVE-2026-1720,#cybersecurity https://cvefind.com/CVE-2026-1720

    Post summary

    A new CVE-2026-1720 vulnerability in WordPress plugin WowOptin, affecting versions up to 1.4.24, allows attackers with limited access to install unauthorized plugins. No patches or exploitation evidence have been reported yet.

    0000037
    596 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1720 The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installat… https://www.cve.org/CVERecord?id=CVE-2026-1720

    Post summary

    The text announces a new vulnerability (CVE‑2026‑1720) affecting a WordPress plugin, highlighting the ability to install arbitrary plugins without authorization, but it provides no PoC, exploit, or mitigation details.

    0000076
    56.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1720 - High The WowOptin: Next-Gen Popup Maker – Create Stunning Popups and Optins for Lead Generation plugin for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing c... https://www.thehackerwire.com/vulnerability/CVE-2026-1720/ https://t.co/iqsNjqZRym

    Post summary

    A high‑severity CVE-2026-1720 affecting the WowOptin WordPress plugin is disclosed, enabling unauthorized arbitrary plugin installation; no PoC, exploit, or patch details are provided.

    0000039
    124 followersView on X

Explore more