Executive brief
Notiqoo is a WordPress plugin for managing automated customer notifications and abandoned cart triggers. The plugin fails to properly restrict access to critical AJAX functions, allowing low-privileged users (such as contributors) to modify core WordPress settings. An attacker can exploit this to deactivate plugins, lock administrators out of the site, or manipulate other critical system options, causing service disruption and loss of administrative control.
Technical details
The vulnerability is an authorization bypass (CWE-863) in multiple AJAX actions within the Notiqoo plugin before version 1.4.14. The affected actions lack capability checks and construct option names from user input without validation. A contributor-role user can forge AJAX requests using a nonce visible in the WordPress admin interface to call actions like woom_autosave_manual_trigger_actions and woom_clear_option, allowing arbitrary modification of WordPress options including wp_user_roles and active_plugins. Additionally, the send_trigger_sample_to_url action requires no authentication at all, enabling unauthenticated webhook exfiltration. The fix is available in version 1.4.14.
Affected products
- Notiqoo Notiqoo before 1.4.14
Timeline
- 2026-09-08: disclosed
- 2026-09-10: patched: Fixed in version 1.4.14