Executive brief
Notification Master is a WordPress plugin that sends real-time notifications via email, SMS, and webhooks. The plugin contains an unauthenticated broken access control flaw that allows attackers to access pages or perform actions they should not be permitted to, such as viewing other users' data, without requiring any valid credentials.
Technical details
The vulnerability is a broken access control flaw in Notification Master plugin versions 1.7.1 and earlier, allowing unauthenticated attackers to bypass authorization checks. The vulnerability permits attackers to access restricted functionality and view sensitive data belonging to other users without authentication. No patch is currently available from the developer. The flaw is rated CVSS 7.5 and classified as OWASP A1 broken access control, indicating it is a high-priority threat expected to be targeted in mass-exploit campaigns.
Affected products
- Notification Master Notification Master 1.7.1 and earlier
Timeline
- 2026-08-24: disclosed
- 2026-07-07: reported: Reported by Ian Ho Shim