WordPress Plugin Vulnerabilities

Adwised Web Push Notification <= 2.5.7 - Unauthenticated Stored XSS via Secret Key Type Juggling

Description

The plugin does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
XSS
CWE
CVSS

Miscellaneous

Original Researcher
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter
Pablo González Pérez, Francisco José Ramírez Vicente and Iñigo Sánchez Enciso
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-10-09 (about 2 days ago)
Added
2026-10-09 (about 1 day ago)
Last Updated
2026-10-09 (about 1 day ago)

Other