CVE-2026-78139 PUBLISHED

Notifima < 3.1.4 - Subscriber+ Stock Alert Unsubscription via IDOR

Assigner: WPScan
Reserved: 23.08.2026 Published: 27.08.2026 Updated: 27.08.2026

The Notifima WordPress plugin before 3.1.4 does not verify that the caller owns the subscription being modified on one of its REST endpoints in all versions up to, and including, 3.1.3, allowing authenticated attackers with Subscriber-level access to unsubscribe arbitrary customers from product stock-alert notifications.

Product Status

Vendor Unknown
Product Notifima
Versions Default: unaffected
  • affected from 0 to 3.1.4 (excl.)

Credits

  • Shikhali Jamalzade finder
  • WPScan coordinator

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE