All push notification for WP <= 1.5.3 - Authenticated (Administrator+) SQL Injection via 'delete_id' Parameter
medium
The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' parameter in all versions up to, and including, 1.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for a...
- CVSS:
- 4.9
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2026
CVE-2026-0816 on NVD →
All push notification for WP [all-push-notification] <= 1.5.3 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 17, 2025
CVE-2025-32546 on NVD →
All push notification for WP <= 1.5.3 - Reflected Cross-Site Scripting
medium
The All push notification for WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they...
- CVSS:
- 6.1
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 14, 2025
CVE-2025-32546 on NVD →
All push notification for WP <= 1.5.3 - Cross-Site Request Forgery to SQL Injection
medium
The All push notification for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.5.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to inject SQL queries via a forged request granted they can...
- CVSS:
- 4.3
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32547 on NVD →
All push notification for WP [all-push-notification] <= 1.5.3 (unfixed)
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP allows Blind SQL Injection. This issue affects All push notification for WP: from n/a through 1.5.3.
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Apr 9, 2025
CVE-2025-32547 on NVD →
All push notification for WP [all-push-notification] <= 1.5.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Mar 3, 2025
CVE-2025-25092 on NVD →
All push notification for WP [all-push-notification] <= 1.5.3 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles allows Stored XSS. This issue affects Easy WP Tiles: from n/a through 1.
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 7, 2025
CVE-2025-25073 on NVD →
All push notification for WP <= 1.5.3 - Unauthenticated Stored Cross-Site Scripting
high
The All push notification for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.5.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whene...
- CVSS:
- 7.2
- Affected:
- up to 1.5.3
- Fix:
- No patched version reported
- Disclosed:
- Feb 3, 2025
CVE-2025-25092 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database