CVE-2026-78139: Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR
The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-level access to unsubscribe arbitrary customers from product stock-alert notifications.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Notifima WordPress pluginto a version that resolves this vulnerability.Fixed in 3.1.4
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated WordPress user with Subscriber-level access can exploit the affected REST endpoint. The attacker does not need elevated administrative privileges.
What is the impact of successful exploitation?
An attacker can unsubscribe arbitrary customers from product stock-alert notifications by modifying subscriptions they do not own.
Which versions are affected?
Notifima versions up to and including 3.1.3 are affected. Version 3.1.4 is identified as the version after the affected range.