{"id":"CVE-2026-7620","title":"The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1","summary":"The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This m…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-862"],"published":"2026-07-11","updated":"2026-07-11","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-7620","references":[{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php#L122","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php#L126","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5.1/include/nftncron.php#L94","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php#L122","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php#L126","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/tags/3.5/include/nftncron.php#L94","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/trunk/include/nftncron.php#L122","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/trunk/include/nftncron.php#L126","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/browser/notification-for-telegram/trunk/include/nftncron.php#L94","label":"security@wordfence.com"},{"url":"https://plugins.trac.wordpress.org/changeset?reponame=&old=3524838%40notification-for-telegram&new=3524838%40notification-for-telegram","label":"security@wordfence.com"},{"url":"https://www.wordfence.com/threat-intel/vulnerabilities/id/01055be6-42ae-405f-9c8b-7acf5297867e?source=cve","label":"security@wordfence.com"}],"tags":["nvd"],"epss":0.00473,"epssPercentile":0.39916,"ingestedAt":"2026-07-11T23:16:20.563Z","slug":"CVE-2026-7620","body":"## Overview\n\nThe Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create, modify, or reschedule the nftb_cron_hook WordPress cron event, enabling unauthorized manipulation of the plugin's background task scheduling logic.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}