WordPress Plugin Vulnerabilities

Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR

Description

The plugin does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-level access to unsubscribe arbitrary customers from product stock-alert notifications.

Proof of Concept

Affects Plugins

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Shikhali Jamalzade
Submitter
Shikhali Jamalzade
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-08-25 (about 3 days ago)
Added
2026-08-25 (about 2 days ago)
Last Updated
2026-08-25 (about 2 days ago)

Other