Executive brief
The Notification for Telegram plugin for WordPress, which allows site owners to send notifications to Telegram, contains a security flaw in its background task management. An attacker with a basic user account on the website can interfere with the plugin's scheduled tasks, potentially disrupting automated notifications. This could lead to missed alerts or operational inconsistencies for site administrators relying on the plugin.
Technical details
The Notification for Telegram plugin for WordPress is vulnerable to an authorization bypass due to missing capability checks in the nftncron.php component. Specifically, the plugin fails to properly verify user permissions before allowing actions on the nftb_cron_hook WordPress cron event. An authenticated attacker with subscriber-level permissions or higher can exploit this via network requests to create, modify, or reschedule background tasks. This enables unauthorized manipulation of the plugin's task scheduling logic, though it does not directly lead to remote code execution or data theft based on the reported CVSS. A fix is available in versions following 3.5.1.
Affected products
- rainafarai Notification for Telegram up to, and including, 3.5.1
Timeline
- 2026-07-11: disclosed
- 2026-07-11: advisory
References
- https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php
- https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php
- https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php
- https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php
- https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php
- https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php
- https://plugins.trac.wordpress.org/browser/notification-for-telegram/trunk/include/nftncron.php