VYPR

Onesignal Free Web Push Notifications

by WordPress

Source repositories

CVEs (3)

  • CVE-2019-15827MedAug 30, 2019
    risk 0.35cvss 5.4epss 0.01

    The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.

  • CVE-2025-13950MedDec 15, 2025
    risk 0.27cvss 5.3epss 0.00

    The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due to the plugin processing POST…

  • CVE-2026-3155LowApr 16, 2026
    risk 0.13cvss 3.1epss 0.00

    The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated…