Cross-Site Request Forgery Vulnerability in Notify Odoo Plugin for WordPress
CVE-2026-8425

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 May 2026

What is CVE-2026-8425?

The Notify Odoo plugin for WordPress is vulnerable to a Cross-Site Request Forgery (CSRF) attack due to inadequate nonce validation in the _updateSettings function. This vulnerability affects all versions up to and including 1.0.1. An unauthenticated attacker could exploit this flaw by crafting a malicious request that alters the Notify Odoo URL to a URL controlled by the attacker. Consequently, this could allow the attacker to change crucial notification settings, tracking image configurations, and allowed IP addresses if a site administrator is tricked into performing an action, such as clicking a deceptive link. It is critical for users to update to the latest version of the plugin to mitigate the risks associated with this vulnerability.

Affected Version(s)

Notify Odoo 0 <= 1.0.1

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abhirup Konwar
.