Junglewise Threat Intelligence

CVE-2026-68564: NotificationX Pro unauthenticated cross-site scripting (XSS)

CVE-2026-68564 · Severity: high · CVSS 7.1 · Published 2026-08-20

Executive brief

NotificationX Pro is a WordPress plugin used to display notifications and alerts on websites. An unauthenticated attacker can inject malicious scripts through the plugin, allowing them to steal visitor data, hijack user accounts, or deface the site. This vulnerability affects all versions up to 3.1.4 and no official patch is currently available.

Technical details

The vulnerability is a reflected or stored Cross-Site Scripting (XSS) flaw in NotificationX Pro plugin versions 3.1.4 and below. The plugin fails to properly sanitize or escape user-supplied input, allowing an unauthenticated attacker to inject malicious JavaScript code. Exploitation can be initiated by an unauthenticated user but requires a privileged user (such as an admin) to click a malicious link or visit a crafted page to trigger the payload. Once executed, the injected script runs in the context of the victim's browser, enabling account hijacking, session theft, or data exfiltration. No official patch has been released; mitigation rules are available through Patchstack.

Affected products

  • NotificationX NotificationX Pro <=3.1.4

Timeline

  • 2026-08-20: disclosed
  • other: Reported to vendor on 2026-06-24

References