VYPR

Adwised Web Push Notification

by WordPress

CVEs (2)

  • CVE-2026-87762Oct 11, 2026
    risk 0.00cvss —epss —

    The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated…

  • CVE-2026-87761Oct 11, 2026
    risk 0.00cvss —epss —

    The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and does not escape those configuration values before printing them inside an inline…