CVE-2026-78563: NotificationX Pro <= 3.1.4 - Unauthenticated Stored Cross-Site Scripting
The NotificationX Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
No authentication or existing WordPress account is required. An unauthenticated remote attacker can inject arbitrary script content through the vulnerable plugin.
Which installations are affected?
NotificationX Pro for WordPress versions up to and including 3.1.4 are affected. The provided data does not identify a safe fixed version.
What happens after malicious content is injected?
The injected script is stored and executes when a user accesses an affected page. The issue can affect confidentiality and integrity, while no availability impact is indicated by the supplied severity vector.