Junglewise Threat Intelligence

CVE-2026-39673: shrikantkale iZooto missing authorization in izooto-web-push

CVE-2026-39673 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

iZooto is a WordPress plugin used by website owners to send web push notifications to their audience. A security flaw in the plugin's access control settings allows unauthorized individuals to perform actions that should be restricted to administrators. This could lead to unauthorized changes in the plugin's configuration or the sending of unintended notifications, potentially impacting the website's reputation and user trust.

Technical details

The iZooto Web Push plugin for WordPress (versions up to and including 3.7.20) is vulnerable to broken access control due to missing authorization checks (CWE-862). This flaw allows an unauthenticated remote attacker to execute functions or modify settings that should be restricted to higher-privileged users. The vulnerability stems from a failure to validate user permissions or verify security nonces before processing certain requests. Attackers can exploit this over the network without any user interaction. A patch is available in version 3.7.21.

Affected products

  • shrikantkale (iZooto) iZooto Web Push <= 3.7.20

Timeline

  • 2026-01-20: other: Vulnerability reported by Nguyen Ba Khanh
  • 2026-02-19: advisory: Initial advisory published by Patchstack
  • 2026-02-19: patched: Patch released in version 3.7.21
  • 2026-04-08: disclosed: CVE published to NVD

References