Impact
The Adwised Web Push Notification WordPress plugin through 2.5.7 allows attackers to store arbitrary JavaScript on the site without requiring authentication. The flaw is caused by missing authorization checks on state‑changing operations and a secret comparison that can be bypassed when the secret key has never been set. Once stored, the code is executed in every visitor’s browser, leading to complete loss of confidentiality and integrity for all users interacting with the site.
Affected Systems
WordPress installations that use the Adwised Web Push Notification plugin version 2.5.7 or earlier, specifically those that have not configured a secret key. The vulnerability is vendor‑agnostic beyond the plugin itself, and any site running these versions is impacted.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity flaw, and the EPSS score of < 1% suggests a low probability of exploitation in the wild; the vulnerability is not yet listed in CISA KEV. The attack path is straightforward and relies on unauthenticated access to admin‑level state‑changing functions. Because the payload is stored, every user will see the malicious script, making the risk high for confidentiality, integrity, and availability of user interactions. The lack of an authentication requirement makes exploitation trivial, and the absence of known mitigations beyond patching further elevates the threat.
OpenCVE Enrichment