Impact
This vulnerability is caused by the Notiqoo WordPress plugin before version 1.4.14 lacking capability checks on several AJAX actions. The plugin builds the option name it writes from unvalidated user input, allowing an authenticated user with the contributor role or higher to set arbitrary WordPress options. An attacker could therefore disable the Notiqoo plugin and lock out all administrators, effectively compromising site control and disrupting service.
Affected Systems
The affected product is the Notiqoo WordPress plugin distributed by the Unknown vendor. Any site running a version older than 1.4.14 is at risk. If the plugin remains active, whether the site is new or has.
Risk and Exploitability
The attack vector is inferred from the description to be standard authenticated web requests to the plugin’s AJAX endpoints, with no additional local or remote exploitation prerequisites. The flaw carries a CVSS score of 6.5, indicating moderate severity, and an EPSS score of less than 1 %, suggesting low but non‑zero exploitation probability in the wild. The vulnerability is not listed in CISA’s KEV catalog. While the exploitability remains moderate, the potential to lock out administrators and disable a security‑related plugin makes the threat significant.
OpenCVE Enrichment