Impact
The NotificationX plugin for WordPress suffers from a missing authorization check that allows attackers to exploit incorrectly configured access control security levels. This broken access control vulnerability can enable unauthorized users to gain access to plugin functions or sensitive configuration data, potentially leading to data tampering or unauthorized changes to notifications.
Affected Systems
WPDeveloper's NotificationX plugin, versions from any starting version up to and including 3.2.1, is affected. The issue spans the entire plugin codebase for those releases.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers could potentially reach the affected code via HTTP requests to the plugin’s administrative interfaces on a WordPress site, though the exact attack path was not detailed in the CVE description, so the inferred vector is remote through web interfaces.
OpenCVE Enrichment