PT-2026-3575 · WordPress · Notificationx

Dmitry Ignatyev

·

Published

2026-01-20

·

Updated

2026-01-21

·

CVE-2026-0554

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions NotificationX plugin for WordPress versions through 3.1.11
Description The NotificationX plugin for WordPress has a flaw that allows unauthorized modification of data. A missing capability check on the ''regenerate'' and ''reset'' REST API endpoints allows authenticated attackers with Contributor-level access or higher to reset analytics for any NotificationX campaign, regardless of ownership. The affected API endpoints are ''/wp-json/notificationx/v1/campaigns/{campaign id}/regenerate'' and ''/wp-json/notificationx/v1/campaigns/{campaign id}/reset'', where campaign id represents the ID of the campaign.
Recommendations Update the NotificationX plugin to a version later than 3.1.11.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-0554

Affected Products

Notificationx