The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated users to disable all of the site's opt-in forms and insert new template-based opt-in rows into the database.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14603 is an authorization bypass vulnerability in the WowOptin WordPress plugin that exposes a REST endpoint without proper authentication checks. This flaw allows unauthenticated attackers to completely disable all opt-in forms on a website and inject arbitrary opt-in rows directly into the database. Any WordPress site running WowOptin before version 1.4.38 is vulnerable, making this particularly dangerous for organizations relying on popup forms for lead generation, user engagement, or critical business functions. The attack requires no credentials and can be executed remotely, making it trivially exploitable at scale.
While this CVE doesn't map to specific MITRE ATT&CK techniques in its current classification, Casky practitioners would detect the underlying attack patterns through skills aligned with CWE-284 (Improper Access Control). Security teams using Casky's Claude AI-powered analysis would identify reconnaissance activity probing REST endpoints for missing authorization checks, followed by anomalous database modifications from unexpected sources—patterns consistent with Application Layer attacks. Practitioners would see unauthorized POST/PUT requests to `/wp-json/` paths, suspicious database entries from unauthenticated sessions, and sudden deactivation of security-critical forms. Extended reasoning across Casky's 754 skills would flag this as a supply-chain risk requiring immediate plugin updates and WAF rules blocking unauthenticated REST access to plugin endpoints.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14603. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation