← WordPress Vulnerabilities
WordPress security by component

Custom New User Notification

Custom New User Notification is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Apr 16, 2026; the highest published CVSS base score is 4.4.

Plugin slug: custom-new-user-notification

CVE-2026-3551: Custom New User Notification: Cross-site scripting

Custom New User Notification is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.2.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.

PublishedApr 16, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for custom-new-user-notification
Safe version
Apr 16, 2026 CVE-2026-3551
Custom New User Notification: Cross-site scripting
Custom New User Notification is affected by cross-site scripting. Exploitation requires an authenticated administrator account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is <= 1.2.0. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE4.4
NVDPending