Description
The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and does not escape those configuration values before printing them inside an inline script block on every front-end page, allowing any authenticated user, such as a subscriber, to perform Stored Cross-Site Scripting attacks against every visitor, including administrators.
Published: 2026-10-11
Score: 8.0 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS affecting all site visitors via plugin configuration by any authenticated user
Action: Immediate Patch
AI Analysis

Impact

The Adwised Web Push Notification WordPress plugin up to version 2.5.7 fails to check user capability or perform nonce validation before accepting configuration changes. It further outputs those configuration values unchanged inside an inline script block on every front‑end page. Consequently, any authenticated user, including a subscriber, can inject arbitrary JavaScript that will run in the browsers of all visitors, including site administrators. This flaw is a classic Stored Cross‑Site Scripting weakness that provides code execution on a wide audience.

Affected Systems

WordPress sites that have the Adwised Web Push Notification plugin installed with a version of 2.5.7 or earlier. The vulnerability exists regardless of the site theme or other plugins because the inline script rendering is performed by the plugin on each front‑end page.

Risk and Exploitability

The flaw has a high exploitation probability in environments where standard WordPress roles such as subscriber are enabled for the plugin's settings page, because attackers only need an authenticated account to set malicious script values. While an exact CVSS score is not supplied in the data, the combination of lack of capability checks and the ability to influence all visitors indicates a severe risk. The EPSS score is not available and the vulnerability is not listed in KEV, but the potential for widespread user impact warrants immediate attention.

Generated by OpenCVE AI on October 11, 2026 at 07:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Adwised Web Push Notification to the latest available version beyond 2.5.7 or remove the plugin entirely if no update exists.
  • Restrict configuration changes for the plugin to administrators only, either by modifying user roles or employing a custom capability check that blocks subscribers from editing settings.
  • Apply a site‑wide Content Security Policy that disallows inline script execution (e.g., script-src 'self' and remove unsafe-inline) to mitigate the impact of any stored scripts that might still be present.

Generated by OpenCVE AI on October 11, 2026 at 07:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and does not escape those configuration values before printing them inside an inline script block on every front-end page, allowing any authenticated user, such as a subscriber, to perform Stored Cross-Site Scripting attacks against every visitor, including administrators.
Title Adwised Web Push Notification <= 2.5.7 - Subscriber+ Stored XSS via Pop-up Settings
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.494Z

Reserved: 2026-09-09T07:22:41.191Z

Link: CVE-2026-87761

cve-icon Vulnrichment

Updated: 2026-10-11T11:20:13.865Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.690

Modified: 2026-10-11T12:17:25.090

Link: CVE-2026-87761

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T07:45:18Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')