Executive brief
The Notification for Telegram plugin for WordPress is vulnerable to a security flaw that allows attackers to inject malicious scripts into the website. This occurs because the plugin does not properly sanitize user-provided data, potentially leading to unauthorized redirects, the display of fraudulent advertisements, or the theft of administrative session information. An exploit is successful when a site administrator or visitor interacts with a specially crafted link or page.
Technical details
A Reflected Cross-Site Scripting (XSS) vulnerability exists in the Notification for Telegram plugin for WordPress (versions 3.5 and below) due to improper neutralization of input during web page generation (CWE-79). The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of a user's browser session by tricking them into clicking a malicious link or visiting a crafted page. Successful exploitation can lead to session hijacking, unauthorized actions on behalf of a logged-in user, or website defacement. The vulnerability is addressed in version 3.5.1.
Affected products
- WordPress Notification for Telegram <= 3.5
Timeline
- 2026-02-11: other: Reported by Nguyen Ba Khanh
- 2026-04-20: advisory: Patchstack advisory published
- 2026-04-20: patched: Version 3.5.1 released
- 2026-06-15: disclosed: NVD publication date