CVE-2026-28153: WordPress Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More plugin <= 1.7.1 - Broken Access Control vulnerability
Unauthenticated Broken Access Control in Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & More <= 1.7.1 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Notification Master – Real-Time WordPress Notifications With Email, SMS, Webhooks & Moreto a version that resolves this vulnerability.Fixed in 1.7.1
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or any existing privileges to exploit an affected site.
Which installations are affected?
Notification Master versions 1.7.1 and earlier are affected. The provided information does not identify any configuration prerequisite, so sites running an affected version should be treated as exposed.
What is the potential impact?
Successful exploitation can expose confidential information. The supplied CVSS vector indicates no integrity or availability impact.