VYPR

Web Push Notification

by WordPress

CVEs (3)

  • CVE-2024-13877HigMar 20, 2025
    risk 0.46cvss 7.1epss 0.00

    The Passbeemedia Web Push Notification WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.

  • CVE-2025-58873MedSep 5, 2025
    risk 0.38cvss 5.9epss 0.00

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification pushe-webpush allows Stored XSS.This issue affects Pushe Web Push Notification: from n/a through <= 0.5.0.

  • CVE-2023-5620MedNov 27, 2023
    risk 0.35cvss 5.4epss 0.00

    The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Stored XSS attacks.