Impact
A flaw in the Notification Master WordPress plugin enables unauthenticated actors to bypass normal access controls. The vulnerability permits attackers to perform privileged operations on the notification system, potentially exposing sensitive configuration data, manipulating automated alerts, or hijacking the notification workflow. The weakness is identified as CWE‑862: Broken Access Control.
Affected Systems
The problem exists in the Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin for versions up to and including 1.7.1. Systems running any affected version of this plugin are vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no currently known widespread exploitation. Attackers can exploit the flaw via the plugin’s web interfaces without authentication, making the risk moderate to high for sites that host the plugin in a publicly reachable environment.
OpenCVE Enrichment