CVE-2026-78139
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-78139 is an Insecure Direct Object Reference (IDOR) vulnerability in the Notifima WordPress plugin that allows authenticated attackers with Subscriber-level access to unsubscribe arbitrary customers from product stock-alert notifications. It affects all versions of the plugin up to and including 3.1.3, with version 3.1.4 containing the fix. The vulnerability was publicly disclosed on August 25, 2026, and assigned a CVSS score of 4.3 (Medium) (WPScan, GitHub Advisory).

Détails techniques

The root cause is a missing ownership verification check on a REST API endpoint within the Notifima plugin (CWE-639: Authorization Bypass Through User-Controlled Key), classified as an IDOR under OWASP Top 10 A5: Broken Access Control. An authenticated user with only Subscriber-level privileges can send a crafted REST API request referencing another customer's subscription identifier, and the plugin will process the modification without confirming the requester owns that subscription. No special configuration or elevated privileges beyond a basic WordPress account are required to exploit this flaw. A proof-of-concept is scheduled for public release on September 8, 2026, to allow time for users to update (WPScan).

Impact

Successful exploitation allows any authenticated WordPress subscriber to unsubscribe arbitrary customers from WooCommerce product stock-alert notifications managed by the Notifima plugin. This primarily affects the integrity and availability of notification services — targeted customers will not receive back-in-stock alerts they opted into, potentially causing missed purchase opportunities and customer dissatisfaction. While the vulnerability does not expose sensitive data or enable remote code execution, it can be used for targeted business disruption against e-commerce stores relying on stock-alert notifications for sales (WPScan, GitHub Advisory).

Exploitabilité

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept at this time, though WPScan has indicated a PoC will be released on September 8, 2026. The EPSS score is 0.0, reflecting low current exploitation probability, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires only a valid WordPress account with Subscriber-level access, making it low-barrier once a PoC is available (WPScan, GitHub Advisory).

Étapes d’exploitation

  1. Obtain a low-privilege account: Register or obtain a Subscriber-level WordPress account on a target site running Notifima < 3.1.4.
  2. Identify the vulnerable REST endpoint: Locate the Notifima REST API endpoint responsible for managing stock-alert subscriptions (e.g., via plugin source code review or API enumeration).
  3. Enumerate subscription IDs: Send authenticated REST API requests with varying subscription identifiers (e.g., incrementing integer IDs) to discover valid subscriptions belonging to other customers.
  4. Send unauthorized unsubscribe request: Craft an authenticated REST API request targeting a discovered subscription ID that belongs to another customer, triggering the unsubscribe action without ownership verification.
  5. Confirm impact: Verify that the targeted customer's stock-alert subscription has been removed, confirming successful exploitation (WPScan).

Indicateurs de compromis

  • Logs: WordPress REST API access logs showing repeated authenticated requests to Notifima subscription endpoints from a single low-privilege user account, particularly with varying subscription IDs in rapid succession.
  • Database: Unexpected bulk removal of entries in the Notifima subscription table (e.g., wp_notifima_subscribers or equivalent) not correlated with legitimate customer opt-outs.
  • Network: Unusual patterns of REST API calls (e.g., POST or DELETE requests to /wp-json/notifima/v*/subscription/*) from a single IP or user agent targeting multiple subscription IDs.

Atténuation et solutions de contournement

Update the Notifima WordPress plugin to version 3.1.4 or later, which introduces proper ownership verification on the affected REST endpoint (WPScan). As a temporary workaround prior to patching, site administrators can restrict REST API access to authenticated users only or temporarily disable the plugin if stock-alert functionality is not critical. Monitoring REST API logs for unusual subscription modification activity is also recommended.

Réactions de la communauté

The vulnerability was discovered and reported by researcher Shikhali Jamalzade (Twitter: @0xAlisAlive), who submitted it through WPScan's responsible disclosure process. No significant broader media coverage or notable community commentary has been identified beyond the standard vulnerability database publications (WPScan).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-78333NONEN/A
  • 12-step-meeting-list
NonOuiAug 27, 2026
CVE-2026-78139NONEN/A
  • woocommerce-product-stock-alert
NonOuiAug 27, 2026
CVE-2026-78138NONEN/A
  • finale-woocommerce-sales-countdown-timer-discount
NonOuiAug 27, 2026
CVE-2026-78137NONEN/A
  • storegrowth-sales-booster
NonOuiAug 27, 2026
CVE-2026-78125NONEN/A
  • learnpress-sepay-payment
NonOuiAug 27, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités