Stored Cross-Site Scripting Vulnerability in NotificationX Pro Plugin by WordPress
CVE-2026-78563

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
25 August 2026

What is CVE-2026-78563?

The NotificationX Pro plugin for WordPress allows unauthenticated users to exploit a vulnerability related to Stored Cross-Site Scripting. This occurs due to inadequate input sanitization and output escaping in versions up to and including 3.1.4. Attackers can inject harmful web scripts into pages, which can be executed when users navigate to the compromised pages, potentially leading to further security issues and data breaches.

Affected Version(s)

NotificationX Pro 0 <= 3.1.4

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh
.