PT-2026-3575 · WordPress · Notificationx
Dmitry Ignatyev
·
Published
2026-01-20
·
Updated
2026-01-21
·
CVE-2026-0554
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NotificationX plugin for WordPress versions through 3.1.11
Description
The NotificationX plugin for WordPress has a flaw that allows unauthorized modification of data. A missing capability check on the ''regenerate'' and ''reset'' REST API endpoints allows authenticated attackers with Contributor-level access or higher to reset analytics for any NotificationX campaign, regardless of ownership. The affected API endpoints are ''/wp-json/notificationx/v1/campaigns/{campaign id}/regenerate'' and ''/wp-json/notificationx/v1/campaigns/{campaign id}/reset'', where
campaign id represents the ID of the campaign.Recommendations
Update the NotificationX plugin to a version later than 3.1.11.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notificationx