Junglewise Threat Intelligence

CVE-2024-6228: WANotifier WordPress plugin local file inclusion in notifier_preview_btn_style

CVE-2024-6228 · Severity: info · CVSS 7.5 · Published 2026-07-06

Vendors: Unknown.

Executive brief

A vulnerability exists in the Notifications for Forms & WordPress Actions plugin for WordPress, which is used to manage form notifications and automated actions. An attacker with a basic user account (such as a subscriber) can trick the system into running unauthorized files already present on the server. This could lead to a full takeover of the website or the theft of sensitive data.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the WANotifier (Notifications for Forms & WordPress Actions) plugin for WordPress prior to version 2.6. The issue stems from a failure to validate user-supplied input in the 'btn_style' parameter within the 'notifier_preview_btn_style' AJAX action. An authenticated attacker with at least Subscriber-level privileges can use directory traversal sequences (e.g., ../) to include and execute arbitrary PHP files located on the server's filesystem. This can lead to remote code execution if the attacker can control the contents of a local file (e.g., via log poisoning or file uploads). The vulnerability is fixed in version 2.6.

Affected products

  • Unknown Notifications for Forms & WordPress Actions (WANotifier) < 2.6

Timeline

  • 2026-06-15: disclosed: Publicly published by Project Black
  • 2026-06-15: patched: Fixed in version 2.6
  • 2026-07-06: advisory: NVD published date

References