CVE-2026-28153
Received Received - Intake

Unauthenticated Broken Access Control in Notification Master WordPress Plugin

Vulnerability report for CVE-2026-28153, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-24

Last updated on: 2026-08-24

Assigner: Patchstack

Description

Unauthenticated Broken Access Control in Notification Master &#8211; Real-Time WordPress Notifications With Email, SMS, Webhooks &amp; More <= 1.7.1 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-24
Last Modified
2026-08-24
Generated
2026-08-24
AI Q&A
2026-08-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
notification_master notification_master to 1.7.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated broken access control vulnerability in the WordPress plugin Notification Master affecting versions 1.7.1 and below. It allows unauthenticated users to perform privileged actions due to missing authorization checks.

Detection Guidance

Check for unauthorized access attempts or unusual activity in WordPress logs, especially related to the Notification Master plugin. Monitor network traffic for suspicious requests targeting the plugin's endpoints. No specific commands are provided in the context.

Impact Analysis

This vulnerability poses a significant risk of mass exploitation, potentially targeting thousands of websites indiscriminately. Attackers could perform unauthorized actions without authentication.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR (data protection) and HIPAA (health information privacy). Unauthorized access risks exposing personal or protected health information, potentially resulting in legal penalties or breaches of regulatory standards.

Mitigation Strategies

Apply Patchstack's temporary mitigation rule to block attacks. Avoid using the plugin until an official patch is released. Consider updating the plugin if a fix becomes available or seek help from a hosting provider or web developer.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-28153. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart