CVE-2026-4302Disclosure

LOWCVSS 7.2 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the plugin exposing a publicly accessible REST API endpoint (optn/v1/integration-action) with a permission_callback of __return_true that passes user-supplied URLs directly to wp_remote_get() and wp_remote_post() in the Webhook::add_subscriber() method without any URL validation or restriction. The plugin does not use wp_safe_remote_get/post which provide built-in SSRF protection. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application, which can be used to query and modify information from internal services.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-04-08: 1PoC Mentioned / Linked · 2026-04-08: 1Technical Details · 2026-03-21: 203-2104-08
Signal classification2 categories
Disclosure
266.7%
PoC
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure2
2026-04-081
PoC1
Full discourse3 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-4302-optin-version-1-4-29-high-vulnerability-proof-of-concept CVE-2026-4302 #WordPress plugin #vulnerability optin #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atomicedge

    Post summary

    The posting links to a proof‑of‑concept for CVE‑2026‑4302 affecting the WordPress Optin plugin, without detailing exploitation tools, patches, or active attacks.

    0000041
    6 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-4302 The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the pl… https://www.cve.org/CVERecord?id=CVE-2026-4302 ----- Traducción: CVE-2026-4302 El … http://infoflow.cloud`

    Post summary

    The post announces that the WowOptin WordPress plugin is vulnerable to SSRF up to version 1.4.29, citing the CVE and providing a link to its record but offering no exploit or patch information.

    0000019
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4302 The WowOptin: Next-Gen Popup Maker plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.4.29. This is due to the pl… https://www.cve.org/CVERecord?id=CVE-2026-4302

    Post summary

    CVE‑2026‑4302 identifies a Server‑Side Request Forgery vulnerability in the WowOptin WordPress plugin up to version 1.4.29; the snippet provides the vulnerability type but no patch, PoC or active exploitation details.

    0000083
    56.8K followersView on X

Explore more