Unrated severityNVD Advisory· Published Oct 11, 2026
CVE-2026-87762
CVE-2026-87762
Description
The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.5.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.