---
id: CVE-2026-19840
title: >-
  The Notiqoo  WordPress plugin before 1.4.14 does not have capability checks on
  several of its AJAX actions and builds the name of the option to write from
  user input, allowing users with a role as low as contributor to modify
  arbitrary W…
summary: >-
  The Notiqoo  WordPress plugin before 1.4.14 does not have capability checks on
  several of its AJAX actions and builds the name of the option to write from
  user input, allowing users with a role as low as contributor to modify
  arbitrary W…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-863
product: Notiqoo
affected:
  - Notiqoo < 1.4.14
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19840'
references:
  - url: 'https://wpscan.com/vulnerability/030939ee-9aa9-4082-934e-c9a07fc3dfc3/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T13:08:31.204840Z'
ingestedAt: '2026-09-10T06:34:51.925Z'
epss: 0.00226
epssPercentile: 0.1181
---

## Overview

The Notiqoo  WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds the name of the option to write from user input, allowing users with a role as low as contributor to modify arbitrary WordPress options, which can be used to deactivate Notiqoo  WordPress plugin before 1.4.14 and to lock every administrator out of the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
