Impact
The Notifima WordPress plugin versions prior to 3.1.4 contain an insecure direct object reference flaw. The plugin’s REST endpoint for managing stock‑alert subscriptions does not verify that the requestor owns the subscription being modified. Consequently, an authenticated user with Subscriber‑level privileges can unsubscribe any customer by specifying an arbitrary subscription ID.
Affected Systems
WordPress sites that have the Notifima plugin version 3.1.3 or earlier installed are affected. All such installations lack the ownership check on the relevant REST endpoint.
Risk and Exploitability
Attackers must first authenticate with a Subscriber account. Once authenticated, they can guess or enumerate subscription identifiers and request unsubscription of other users. No public exploit is publicly documented, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.3 indicates medium severity and the EPSS score of <1% suggests a low likelihood of exploitation in the wild.
OpenCVE Enrichment