Cross-Site Request Forgery Vulnerability in Notify Odoo Plugin for WordPress
CVE-2026-8425
What is CVE-2026-8425?
The Notify Odoo plugin for WordPress is vulnerable to a Cross-Site Request Forgery (CSRF) attack due to inadequate nonce validation in the _updateSettings function. This vulnerability affects all versions up to and including 1.0.1. An unauthenticated attacker could exploit this flaw by crafting a malicious request that alters the Notify Odoo URL to a URL controlled by the attacker. Consequently, this could allow the attacker to change crucial notification settings, tracking image configurations, and allowed IP addresses if a site administrator is tricked into performing an action, such as clicking a deceptive link. It is critical for users to update to the latest version of the plugin to mitigate the risks associated with this vulnerability.
Affected Version(s)
Notify Odoo 0 <= 1.0.1