Executive brief
The Notify Odoo plugin for WordPress, which integrates WordPress sites with Odoo business software, is vulnerable to a security flaw that allows attackers to change its settings. By tricking a site administrator into clicking a malicious link, an attacker can redirect notifications to their own servers or modify tracking and IP security settings. This could lead to the redirection of sensitive business data or the bypassing of certain access controls.
Technical details
The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the _updateSettings function in versions up to 1.0.1. An unauthenticated attacker can exploit this by crafting a malicious request and using social engineering to trick a site administrator into executing it (e.g., via a phishing link). Successful exploitation allows the attacker to modify critical plugin configurations, such as the Notify Odoo URL, tracking image settings, and allowed IP addresses. This can result in data redirection to attacker-controlled infrastructure or unauthorized configuration changes.
Affected products
- Notify Odoo Notify Odoo Up to, and including, 1.0.1
Timeline
- 2026-05-15: disclosed: CVE published by Wordfence/NVD
References
- https://plugins.trac.wordpress.org/browser/notify-odoo/tags/1.0.1/Controller/Adminhtml/No/Settings.php
- https://plugins.trac.wordpress.org/browser/notify-odoo/tags/1.0.1/Controller/Adminhtml/No/Settings.php
- https://plugins.trac.wordpress.org/browser/notify-odoo/tags/1.0.1/view/adminhtml/templates/no/settings.php
- https://plugins.trac.wordpress.org/browser/notify-odoo/trunk/Controller/Adminhtml/No/Settings.php
- https://plugins.trac.wordpress.org/browser/notify-odoo/trunk/Controller/Adminhtml/No/Settings.php
- https://plugins.trac.wordpress.org/browser/notify-odoo/trunk/view/adminhtml/templates/no/settings.php
- https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3531377%40notify-odoo&new=3531377%40notify-odoo&sfp_email=&sfph_mail=