CVE-2026-68564: WordPress NotificationX Pro plugin <= 3.1.4 - Cross Site Scripting (XSS) vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
Affected Software
1 affected component
WordPress NotificationX Pro plugin<=3.1.4
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to exploit this issue?
The issue is unauthenticated, so no WordPress account or plugin privileges are required. Exploitation still requires user interaction, as indicated by the UI:R vector.
2
What is the potential impact if exploitation succeeds?
The reported CVSS vector indicates low-impact compromise of confidentiality, integrity, and availability, with scope changed. In practice, the issue is categorized as cross-site scripting and can affect users who interact with attacker-supplied content.
3
Which plugin versions are affected?
NotificationX Pro versions 3.1.4 and earlier are identified as affected.