Description
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Published: 2026-08-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated Cross Site Scripting flaw present in the NotificationX Pro WordPress plugin up to version 3.1.4. It allows an attacker to inject malicious JavaScript into web pages served by the site, potentially leading to session hijacking, defacement, or theft of sensitive data. This weakness is a typical CWE‑79 input validation problem where user–controlled data is reflected without proper sanitization.

Affected Systems

The affected product is NotificationX Pro, a WordPress plugin. All installations of version 3.1.4 or earlier are vulnerable. No further version detail is provided beyond the limiting threshold.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity, while no EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, suggesting moderate public exploitation risk. Attackers can exploit the flaw by delivering crafted input to any visitor of the affected site, as authentication is not required.

Generated by OpenCVE AI on August 20, 2026 at 21:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade NotificationX Pro to version 3.1.5 or later.
  • If an update cannot be applied immediately, disable the NotificationX Pro plugin to remove the vulnerable code from the runtime.
  • In the interim, configure a Content Security Policy that blocks inline script execution to reduce the impact of possible XSS injections.

Generated by OpenCVE AI on August 20, 2026 at 21:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Notificationx
Notificationx notificationx Pro
Wordpress
Wordpress wordpress
Vendors & Products Notificationx
Notificationx notificationx Pro
Wordpress
Wordpress wordpress

Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Title WordPress NotificationX Pro plugin <= 3.1.4 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Notificationx Notificationx Pro
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T14:34:48.448Z

Reserved: 2026-07-31T06:24:41.650Z

Link: CVE-2026-68564

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:36.190

Modified: 2026-08-20T15:18:20.800

Link: CVE-2026-68564

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:09:48Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')