Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-87761
CVE-2026-87761
Description
The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and does not escape those configuration values before printing them inside an inline script block on every front-end page, allowing any authenticated user, such as a subscriber, to perform Stored Cross-Site Scripting attacks against every visitor, including administrators.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.5.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.