Description
The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.
Published: 2026-10-11
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthenticated Stored XSS
Action: Patch
AI Analysis

Impact

The Adwised Web Push Notification WordPress plugin through 2.5.7 allows attackers to store arbitrary JavaScript on the site without requiring authentication. The flaw is caused by missing authorization checks on state‑changing operations and a secret comparison that can be bypassed when the secret key has never been set. Once stored, the code is executed in every visitor’s browser, leading to complete loss of confidentiality and integrity for all users interacting with the site.

Affected Systems

WordPress installations that use the Adwised Web Push Notification plugin version 2.5.7 or earlier, specifically those that have not configured a secret key. The vulnerability is vendor‑agnostic beyond the plugin itself, and any site running these versions is impacted.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity flaw, and the EPSS score of < 1% suggests a low probability of exploitation in the wild; the vulnerability is not yet listed in CISA KEV. The attack path is straightforward and relies on unauthenticated access to admin‑level state‑changing functions. Because the payload is stored, every user will see the malicious script, making the risk high for confidentiality, integrity, and availability of user interactions. The lack of an authentication requirement makes exploitation trivial, and the absence of known mitigations beyond patching further elevates the threat.

Generated by OpenCVE AI on October 11, 2026 at 14:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Adwised Web Push Notification plugin to the latest version that includes the fix for the unauthenticated stored XSS issue.
  • Configure a non‑empty secret key for the plugin; if a key exists, reset it to a unique value to avoid the type‑juggling bypass.
  • If an immediate upgrade is not possible, temporarily disable or remove the plugin until a patched release is available.

Generated by OpenCVE AI on October 11, 2026 at 14:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 11 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Sun, 11 Oct 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.
Title Adwised Web Push Notification <= 2.5.7 - Unauthenticated Stored XSS via Secret Key Type Juggling
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-10-11T11:32:43.386Z

Reserved: 2026-09-09T07:22:43.303Z

Link: CVE-2026-87762

cve-icon Vulnrichment

Updated: 2026-10-11T11:19:59.708Z

cve-icon NVD

Status : Received

Published: 2026-10-11T07:17:26.803

Modified: 2026-10-11T12:17:25.243

Link: CVE-2026-87762

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')