VYPR

Web Push Notifications

by webpushr

CVEs (2)

  • CVE-2023-35041HigNov 13, 2023
    risk 0.57cvss 8.8epss 0.00

    Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webpushr plugin <= 4.34.0 versions.

  • CVE-2023-5620MedNov 27, 2023
    risk 0.35cvss 5.4epss 0.00

    The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.