Skip to main content

Vendor/product archive

wpdeveloper / notificationx CVEs

Beta · best-effort

4 CVEs tagged to wpdeveloper / notificationx2 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.

CVE-2025-22683

Published Feb 3, 2025

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPDeveloper NotificationX notificationx allows Stored XSS.This issue affects…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-1698

Published Feb 27, 2024

The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' pa…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-36744

Published Jul 1, 2023

The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-0349

Published Mar 7, 2022

The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Inject…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1