Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification pushe-webpush allows Stored XSS.This issue affects Pushe Web Push Notification: from n/a through <= 0.5.0.
Published: 2025-09-05
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can inject malicious JavaScript into the pushe Web Push Notification plugin. This is a CWE‑79 vulnerability, involving improper neutralization of input. The flaw allows stored XSS because the plugin does not properly neutralize user‑supplied input when rendering a web page. When a user—including an author, editor, or visitor—visits a page containing the compromised data, the embedded script runs in the victim’s browser. This could lead to session hijacking, credential theft, or the execution of arbitrary commands that affect the site’s confidentiality, integrity, or availability.

Affected Systems

The vulnerability afflicts the WordPress “pushe Web Push Notification” plugin released by pusheco. It affects all versions from the initial release up to and including 0.5.0. WordPress sites that have not upgraded beyond 0.5.0 and continue to use the plugin are at risk.

Risk and Exploitability

The CVSS score is 5.9, indicating moderate severity. EPSS indicates a probability of exploitation below 1 %, suggesting that active attacks are unlikely at present. The flaw is not listed in the CISA KEV catalog, further implying lower real‑world exploitation. However, the relatively low EPSS does not eliminate risk, especially for high‑traffic or high‑value sites that might attract targeted attackers. Based on the description, it is inferred that attackers would need to inject a malicious payload through a writable input handled by the plugin, and the impact would be realized when other users load the affected page.

Generated by OpenCVE AI on April 30, 2026 at 15:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the pushe Web Push Notification plugin to a version newer than 0.5.0 or apply any vendor‑provided patch.
  • If upgrading is not immediately possible, remove or disable the plugin’s input fields that accept unsanitized data and ensure output is escaped with a proper HTML‑encoding function.
  • Restrict administrative access to the plugin’s settings and monitor the site for new XSS errors or unexpected script execution.

Generated by OpenCVE AI on April 30, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26904 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification allows Stored XSS. This issue affects Pushe Web Push Notification: from n/a through 0.5.0.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification allows Stored XSS. This issue affects Pushe Web Push Notification: from n/a through 0.5.0. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification pushe-webpush allows Stored XSS.This issue affects Pushe Web Push Notification: from n/a through <= 0.5.0.
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Sun, 07 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Fri, 05 Sep 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Sep 2025 14:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in pusheco Pushe Web Push Notification allows Stored XSS. This issue affects Pushe Web Push Notification: from n/a through 0.5.0.
Title WordPress Pushe Web Push Notification Plugin <= 0.5.0 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-05-12T00:42:57.367Z

Reserved: 2025-09-05T10:50:17.982Z

Link: CVE-2025-58873

cve-icon Vulnrichment

Updated: 2025-09-05T14:41:39.666Z

cve-icon NVD

Status : Deferred

Published: 2025-09-05T14:16:03.977

Modified: 2026-04-23T15:33:48.087

Link: CVE-2025-58873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:30:16Z

Weaknesses