N/A
2026-01-20< 3.2.1
NotificationX <= 3.1.11 - Missing Authorization to Authenticated (Contributor+) Analytics Reset
Minimum safe version
3.2.2
Update to 3.2.2 or later to address 15 fixable vulnerabilities
NotificationX <= 3.1.11 - Missing Authorization to Authenticated (Contributor+) Analytics Reset
CVE-2026-27042
CVE-2025-15380
CVE-2025-22683
CVE-2024-11727
CVE-2024-1698
NotificationX < 2.3.12 - Unauthenticated SQLi
CVE-2020-36744
CVE-2021-4342
Various Affected Software (Various Versions) - Cross-Site Request Forgery Bypass
NotificationX <= 2.3.11 - SQL Injection
Multiple Plugins/Themes - Cross-Site Request Forgery (CSRF)
WordPress NotificationX plugin <= 1.8.2 - Cross-Site Request Forgery (CSRF) vulnerability
WordPress NotificationX plugin <= 2.3.11 - Unauthenticated SQL Injection (SQLi) vulnerability
CVE-2022-0349