NotificationX WordPress Plugin Missing Authorization Vulnerability Allows Analytics Reset

Vulnerability

A vulnerability exists in the NotificationX plugin for WordPress, in all versions through 3.1.11. The issue stems from a lack of proper capability checks on the 'regenerate' and 'reset' REST API endpoints. This flaw enables authenticated attackers with Contributor-level access or higher to reset analytics for any NotificationX campaign, regardless of ownership.

Impact

Exploitation of this vulnerability allows for unauthorized resetting of analytics data on NotificationX campaigns, potentially disrupting campaign performance tracking and management.

Remediation

Users can update to version 3.2.1 or a newer patched version to address this vulnerability.

Added: Jan 20, 2026, 3:59 PM
Updated: Jan 20, 2026, 3:59 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
5.7
remediation
7.7
relevance
2.3
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.