Notify Odoo
Notify Odoo has 2 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 2 are fixed as of September 2026. Their average CVSS score is 5.2, and the most serious one scores 6.1 out of 10.
The most common weakness is Cross-Site Request Forgery (CSRF), behind 2 of the records (100%).
Every one of the 2 issues recorded for Notify Odoo has a vendor fix available, so running the current release closes all known holes.
2 independent researchers contributed these findings, one record each. Notify Odoo is installed on roughly 90 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.8.8.
CVE-2024-56299Notify Odoo <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Notify Odoo
Author
Pektsekye
This plugin sends a notification to the Odoo website when a new order is created on the WooCommerce website. In two minutes the Odoo website sends a request to the WooCommerce website to get the new order data and then saves it as a new order on the Odoo website. Requires WooCommerce API v3 (it is available on WooCommerce 3.5.x or later and WordPress 4.4 or later) And Odoo 11 or later On the Odoo website the Enotif WooCommerce Order module should be installed. For Odoo Online (or if you cannot install third party modules) there is a modified version of this plugin that uses odoo API to send orders. You can download it on the modifications page: http://hottons.com/no_modifications Features: Notifies Odoo about new order and then the new order is saved on the Odoo website. Can import all orders from WooCommerce to Odoo You can read the installation instructions here: README Contact me by email pektsekye@gmail.com if you have questions or need help. Translators Available Languages English (Default) Documentation Full documentation is available here.
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C