Stored Cross-Site Scripting Vulnerability in NotificationX Pro Plugin by WordPress
CVE-2026-78563
7.2HIGH
What is CVE-2026-78563?
The NotificationX Pro plugin for WordPress allows unauthenticated users to exploit a vulnerability related to Stored Cross-Site Scripting. This occurs due to inadequate input sanitization and output escaping in versions up to and including 3.1.4. Attackers can inject harmful web scripts into pages, which can be executed when users navigate to the compromised pages, potentially leading to further security issues and data breaches.
Affected Version(s)
NotificationX Pro 0 <= 3.1.4