Cyklodev WP Notify

Cyklodev WP Notify has one disclosed vulnerability in the WordSec catalog, all reported in 2022; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.

The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).

The one issue recorded for Cyklodev WP Notify has a vendor fix available, so running the current release closes it.

All of these findings were reported by Hoang Van Hiep. The current release is tested up to WordPress 6.1.12.

Strategic Overview

Avg CVSSMedium
5.5/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Cyklodev WP Notify vulnerabilities before they are exploited.

Highest severity on recordCVSS 5.5CVE-2022-44625

Cyklodev WP Notify <= 1.2.1 - Authenticated (Admin+) Stored Cross-Site Scripting

Read the full analysis

Vulnerability Records

1 records
Plugin Profile
Latestv1.3.5

Cyklodev WP Notify

zephilou

Author

zephilou

0.0(0)
0/100
Last Updated
2022-12-15 (4y ago)
Active Installs
0+
Downloads
1,608
Requires WP
6.0.0+
Requires PHP
0+
Tested up to
WP 6.1.12
Created
2014-02-07 (13y ago)

Cyklodev WP Notify add a link in posts list page and also add a metabox in edit page. By following the link you will be able to send the notification of a particular article to all users within a role. It also allow you to tweet the article via your Twitter application.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C