The NotificationX plugin for WordPress is vulnerable to a security issue called Cross-Site Request Forgery (CSRF). This means that versions up to, and including, 1.8.2 may be vulnerable if the plugin is not up-to-date. A nonce validation on the generate_conversions() function is missing or incorrect. This security issue could allow an unauthenticated attacker to create a forged request and trick a site administrator into clicking a link.