Medium severity5.4NVD Advisory· Published Nov 27, 2023· Updated Jun 17, 2026
CVE-2023-5620
CVE-2023-5620
Description
The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:webpushr:web_push_notifications:*:*:*:*:*:wordpress:*:*Range: <4.35.0
- Range: <4.35.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/a03330c2-3ae0-404d-a114-33b18cc47666nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.