WordPress Plugin Vulnerabilities

Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions

Description

The plugin does not have capability checks on several of its AJAX actions and builds the name of the option to write from user input, allowing users with a role as low as contributor to modify arbitrary WordPress options, which can be used to deactivate plugins and to lock every administrator out of the site.

Proof of Concept

Affects Plugins

Fixed in 1.4.14

References

Classification

Type
INCORRECT AUTHORISATION
CWE

Miscellaneous

Original Researcher
Seongwon Lee
Submitter
Seongwon Lee
Verified
Yes

Timeline

Publicly Published
2026-09-08 (about 2 days ago)
Added
2026-09-08 (about 1 day ago)
Last Updated
2026-09-08 (about 1 day ago)

Other