CVE-2026-19840: Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions
The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds the name of the option to write from user input, allowing users with a role as low as contributor to modify arbitrary WordPress options, which can be used to deactivate Notiqoo WordPress plugin before 1.4.14 and to lock every administrator out of the site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Notiqoo WordPress pluginto a version that resolves this vulnerability.Fixed in 1.4.14
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with at least the Contributor role can exploit the affected AJAX actions. The issue does not require administrator-level permissions.
What is the impact of successful exploitation?
An attacker can modify arbitrary WordPress options. The described outcomes include deactivating the Notiqoo plugin and locking all administrators out of the site.
Which installations are affected?
Notiqoo versions earlier than 1.4.14 are affected. The vulnerability is in several AJAX actions that lack capability checks.