Impact
This is a broken access control flaw that allows attackers to manipulate subscriber features of the WordPress Push Notification for Post and BuddyPress plugin. The vulnerability enables unauthorized creation, modification, or deletion of push notification data that subscribers receive. Although it does not grant arbitrary code execution or system compromise, the exposed control could lead to privacy violations or disruption of communication for legitimate users.
Affected Systems
Any WordPress installation that employs the Push Notification for Post and BuddyPress plugin version 3.20 or older is affected. Site administrators should verify installed plugin versions and identify sites requiring an upgrade.
Risk and Exploitability
The CVSS score of 5.4 signals moderate severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV. The attack vector is inferred to be via the web interface, where a crafted request can bypass legitimate access checks. Although it does not provide remote code execution, the flaw permits unauthorized manipulation of notification content within the affected system.
OpenCVE Enrichment