Unauthenticated Access Control Flaw in Notification Master Plugin for WordPress
CVE-2026-28153
7.5HIGH
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 24 August 2026
What is CVE-2026-28153?
The Notification Master plugin for WordPress, versions 1.7.1 and earlier, is susceptible to an unauthenticated broken access control vulnerability. This issue could allow attackers to gain unauthorized access to restricted functionalities, potentially compromising the security of the website and its data. Website administrators are urged to review their installations and take necessary actions to mitigate risks associated with this vulnerability.
Affected Version(s)
Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1