Extension WordPress
Vulnérabilités NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
Cette page rassemble les failles publiées pour NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar
9 fiches
NotificationX <= 3.1.11 – Missing Authorization to Authenticated (Contributor+) Analytics Reset
The NotificationX plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'regenerate' and 'reset' REST API endpoints in all versions up to, and including, 3.1.11. This makes it possible…
*-3.1.11
3.2.1
20/01/2026
NotificationX <= 3.2.0 – Unauthenticated DOM-Based Cross-Site Scripting via 'nx-preview'
The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to,…
*-3.2.0
3.2.1
20/01/2026
NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar <= 3.2.1 – Missing Authorization
The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all…
*-3.2.1
3.2.2
15/01/2026
NotificationX <= 2.9.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The NotificationX plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 2.9.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above,…
*-2.9.5
3.0.0
31/01/2025
NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar <= 2.9.3 – Authenticated (Admin+) Stored Cross-Site Scripting
The NotificationX – Live Sales Notification, WooCommerce Sales Popup, FOMO, Social Proof, Announcement Banner & Floating Notification Top Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's content settings for notifications in all versions…
*-2.9.3
2.9.4
11/12/2024
NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor <= 2.8.2 – Unauthenticated SQL Injection
The NotificationX – Best FOMO, Social Proof, WooCommerce Sales Popup & Notification Bar Plugin With Elementor plugin for WordPress is vulnerable to SQL Injection via the 'type' parameter in all versions up to, and including, 2.8.2 due to…
*-2.8.2
2.8.3
26/02/2024
NotificationX <= 2.3.11 – SQL Injection
The NotificationX plugin for WordPress is vulnerable to generic SQL Injection via the ‘id’ parameter found within the notificationx/v1/notification REST endpoint in versions up to, and including, 2.3.11 due to insufficient escaping on the user supplied parameter and…
*-2.3.11
2.3.12
28/02/2022
NotificationX <= 2.3.8 – Blind SQL Injection
The NotificationX WordPress plugin before 2.3.9 does not sanitise and escape the nx_id parameter before using it in a SQL statement, leading to an Unauthenticated Blind SQL Injection.
*-2.3.8
2.3.9
02/02/2022
NotificationX <= 1.8.2 – Cross-Site Request Forgery Bypass
The NotificationX plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.8.2. This is due to missing or incorrect nonce validation on the generate_conversions() function. This makes it possible for unauthenticated attackers…
[*, 1.8.3)
1.8.3
16/09/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.