Junglewise Threat Intelligence

CVE-2026-40732: WordPress Notification for Telegram unauthenticated XSS

CVE-2026-40732 · Severity: high · CVSS 7.1 · Published 2026-06-15

Vendors: Wordpress.

Executive brief

The Notification for Telegram plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs because the plugin does not properly sanitize user-provided data, potentially leading to unauthorized redirects, the display of fraudulent advertisements, or the theft of administrative session information. An exploit is successful when a site administrator or visitor interacts with a specially crafted link or page.

Technical details

A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Notification for Telegram plugin for WordPress (versions 3.5 and below) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a user's browser session by tricking them into clicking a malicious link or visiting a crafted page. Successful exploitation can lead to session hijacking, unauthorized actions on behalf of a logged-in user, or website defacement. The vulnerability is addressed in version 3.5.1.

Affected products

  • WordPress Notification for Telegram <= 3.5

Timeline

  • 2026-02-11: other: Reported by Nguyen Ba Khanh
  • 2026-04-20: advisory: Patchstack advisory published
  • 2026-04-20: patched: Version 3.5.1 released
  • 2026-06-15: disclosed: NVD publication date

References