Executive brief
A vulnerability exists in the Notifications for Forms & WordPress Actions plugin for WordPress, which is used to manage form notifications and automated actions. An attacker with a basic user account (such as a subscriber) can trick the system into running unauthorized files already present on the server. This could lead to a full takeover of the website or the theft of sensitive data.
Technical details
A Local File Inclusion (LFI) vulnerability exists in the WANotifier (Notifications for Forms & WordPress Actions) plugin for WordPress prior to version 2.6. The issue stems from a failure to validate user-supplied input in the 'btn_style' parameter within the 'notifier_preview_btn_style' AJAX action. An authenticated attacker with at least Subscriber-level privileges can use directory traversal sequences (e.g., ../) to include and execute arbitrary PHP files located on the server's filesystem. This can lead to remote code execution if the attacker can control the contents of a local file (e.g., via log poisoning or file uploads). The vulnerability is fixed in version 2.6.
Affected products
- Unknown Notifications for Forms & WordPress Actions (WANotifier) < 2.6
Timeline
- 2026-06-15: disclosed: Publicly published by Project Black
- 2026-06-15: patched: Fixed in version 2.6
- 2026-07-06: advisory: NVD published date