WordPress · Notification For Telegram · CVE-2026-7620
**Name of the Vulnerable Software and Affected Versions**
Notification for Telegram versions prior to 3.5.2
**Description**
The Notification for Telegram plugin for WordPress contains an authorization bypass. The plugin fails to properly verify if a user is authorized to perform specific actions, allowing authenticated attackers with subscriber-level access or higher to manipulate the plugin's background task scheduling logic. This is achieved by creating, modifying, or rescheduling the `nftb cron hook` WordPress cron event via the `nftb cron action set` AJAX action.
**Recommendations**
Update Notification for Telegram to version 3.5.2 or later.