Briefing

CVE-2026-31431 Public Notifications Vulnerability in theori-io Plugin

security
by mfi · CVE-2026-31431

Patch the theori‑io plugin immediately by applying the latest release or the provided patch to enforce authentication on notification settings.

What to do now

Patch the plugin immediately, verify that the issue is resolved, and monitor for any related exploits.

Summary

On May 5 2026, the theori‑io repository reported a critical vulnerability identified as CVE‑2026‑31431 that affects the public notifications feature of the plugin. The flaw allows unauthenticated users to modify notification settings because the code fails to enforce a sign‑in check before permitting changes. The issue was logged as issue #128 and has already attracted attention, with the project boasting 735 forks and 3.4 k stars on GitHub. The vulnerability is present in the current stable release and could be exploited to alter notification behavior or potentially inject malicious content. Affected users are urged to update immediately, as the plugin does not yet provide a patch in the release channel. The maintainer has not yet released a fix, but the issue remains open with no assignee. The CVE is classified as a high‑severity flaw that could lead to unauthorized configuration changes. Users should verify that the plugin’s notification endpoint requires authentication before applying any changes.

Key changes

  • CVE‑2026‑31431 identified in theori‑io public notifications feature.
  • Vulnerability allows unauthenticated users to change notification settings.
  • Issue opened May 5 2026 as issue #128.
  • Repository has 735 forks and 3.4 k stars on GitHub.
  • No patch released yet; issue remains open with no assignee.
  • High‑severity flaw could lead to unauthorized configuration changes.
  • Affected plugin version is the current stable release.
  • Users must enforce authentication before modifying notification settings.

Affects

wp-customers

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting