Impact
The Adwised Web Push Notification WordPress plugin up to version 2.5.7 fails to check user capability or perform nonce validation before accepting configuration changes. It further outputs those configuration values unchanged inside an inline script block on every front‑end page. Consequently, any authenticated user, including a subscriber, can inject arbitrary JavaScript that will run in the browsers of all visitors, including site administrators. This flaw is a classic Stored Cross‑Site Scripting weakness that provides code execution on a wide audience.
Affected Systems
WordPress sites that have the Adwised Web Push Notification plugin installed with a version of 2.5.7 or earlier. The vulnerability exists regardless of the site theme or other plugins because the inline script rendering is performed by the plugin on each front‑end page.
Risk and Exploitability
The flaw has a high exploitation probability in environments where standard WordPress roles such as subscriber are enabled for the plugin's settings page, because attackers only need an authenticated account to set malicious script values. While an exact CVSS score is not supplied in the data, the combination of lack of capability checks and the ability to influence all visitors indicates a severe risk. The EPSS score is not available and the vulnerability is not listed in KEV, but the potential for widespread user impact warrants immediate attention.
OpenCVE Enrichment