The Notification for Telegram plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.5.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to create, modify, or reschedule the nftb_cron_hook WordPress cron event, enabling un [truncated]
CVE-2026-40732 is an Unauthenticated Cross Site Scripting (XSS) vulnerability affecting the Notification for Telegram plugin up to version 3.5. The vulnerability has a CVSS score of 7.1, indicating a HIGH severity level. The CVE was published on 2026-06-15T21:16:48.763Z and last modified on 2026-06-15T21:24:32.790Z.