PT-2026-57401 · WordPress · Notification For Telegram

·

CVE-2026-7620

·

Published

2026-07-11

·

Updated

2026-07-11

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Notification for Telegram versions prior to 3.5.2
Description The Notification for Telegram plugin for WordPress contains an authorization bypass. The plugin fails to properly verify if a user is authorized to perform specific actions, allowing authenticated attackers with subscriber-level access or higher to manipulate the plugin's background task scheduling logic. This is achieved by creating, modifying, or rescheduling the nftb cron hook WordPress cron event via the nftb cron action set AJAX action.
Recommendations Update Notification for Telegram to version 3.5.2 or later.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7620

Affected Products

Notification For Telegram