Unauthenticated Access Control Flaw in Notification Master Plugin for WordPress
CVE-2026-28153

7.5HIGH

What is CVE-2026-28153?

The Notification Master plugin for WordPress, versions 1.7.1 and earlier, is susceptible to an unauthenticated broken access control vulnerability. This issue could allow attackers to gain unauthorized access to restricted functionalities, potentially compromising the security of the website and its data. Website administrators are urged to review their installations and take necessary actions to mitigate risks associated with this vulnerability.

Affected Version(s)

Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ian Ho Shim | Patchstack Bug Bounty Program
.