Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP all-push-notification allows Reflected XSS.This issue affects All push notification for WP: from n/a through <= 1.5.3.
Published: 2025-03-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The All push notification for WP plugin implements a Reflected XSS flaw due to insufficient input sanitization. This flaw can be triggered when an attacker supplies crafted data that is later rendered in a web page. If an authenticated or unauthenticated user views the affected page, the attacker can inject arbitrary JavaScript that may hijack sessions, alter page content, or launch phishing attacks.

Affected Systems

Any WordPress site using the All push notification for WP plugin by gtlwpdev with a version equal to or older than 1.5.3 is affected. Versions earlier than the initial release also remain vulnerable if the plugin has not been updated. Site administrators should verify the installed plugin version and confirm that it is 1.5.4 or newer.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high risk. The EPSS score is below 1%, implying that active exploitation is unlikely at present. However, the vulnerability is not contained within CISA's KEV list, so no dedicated mitigation guidance exists. The likely attack vector is reflected XSS, which requires an attacker to entice a victim into visiting a manipulated URL or interacting with a malicious form that includes the vulnerable input. Successful exploitation would occur entirely on the client side, potentially giving attackers significant control over the victim’s browser session.

Generated by OpenCVE AI on May 1, 2026 at 14:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the plugin to version 1.5.4 or later which removes the vulnerability.
  • If an update is not immediately possible, remove or disable the All push notification for WP plugin to eliminate the attack surface.
  • Deploy a strict Content Security Policy that disallows inline scripts and restricts script sources to trusted origins.

Generated by OpenCVE AI on May 1, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-5662 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP all-push-notification allows Reflected XSS.This issue affects All push notification for WP: from n/a through <= 1.5.3.
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 03 Mar 2025 13:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.
Title WordPress All push notification for WP plugin <= 1.5.3 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:35.284Z

Reserved: 2025-02-03T13:34:21.524Z

Link: CVE-2025-25092

cve-icon Vulnrichment

Updated: 2025-03-03T16:00:17.974Z

cve-icon NVD

Status : Deferred

Published: 2025-03-03T14:15:50.343

Modified: 2026-04-23T15:25:33.803

Link: CVE-2025-25092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T14:45:16Z

Weaknesses