plugin

Push Notification For Post And Buddypress Vulnerabilities

9 known security issues reported for the Push Notification For Post And Buddypress WordPress plugin. Most recent disclosed Feb 14, 2025.

1 critical 3 medium

Running Push Notification For Post And Buddypress on your site? Check whether your installed version is affected.

Scan your site free

Push Notification for Post and BuddyPress [push-notification-for-post-and-buddypress] < 2.12

unknown

[en] Missing Authorization vulnerability in Murali Push Notification for Post and BuddyPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Push Notification for Post and BuddyPress: from n/a through 2.11.

Affected:
up to 2.12
Fixed in:
2.12
Disclosed:
Feb 14, 2025

CVE-2025-23771 on NVD →

Push Notification for Post and BuddyPress <= 2.11 - Missing Authorization to Unauthenticated Settings Update

medium

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.11. This makes it possible for unauthenticated attackers to update the plugin's settings.

CVSS:
5.3
Affected:
up to 2.11
Fixed in:
2.12
Disclosed:
Jan 16, 2025

CVE-2025-23771 on NVD →

Push Notification for Post and BuddyPress [push-notification-for-post-and-buddypress] < 2.08

unknown

[en] The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, and including, 2.06 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to in...

Affected:
up to 2.08
Fixed in:
2.08
Disclosed:
Jan 11, 2025

CVE-2024-12407 on NVD →

Push Notification for Post and BuddyPress <= 2.07 - Reflected Cross-Site Scripting

medium

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, and including, 2.07 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject...

CVSS:
6.1
Affected:
up to 2.06
Fixed in:
2.08
Disclosed:
Jan 10, 2025

CVE-2024-12407 on NVD →

Push Notification for Post and BuddyPress <= 1.93 - Unauthenticated SQL Injection

critical

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to SQL Injection via the 'onesignal_externalid' and 'onesignal_get_subscriptionoptions_id' paramters in all versions up to, and including, 1.93 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation...

CVSS:
10
Affected:
up to 1.93
Fixed in:
1.94
Disclosed:
May 27, 2024

CVE-2024-6159 on NVD →

Push Notification for Post and BuddyPress [push-notification-for-post-and-buddypress] < 1.64

unknown

Update the WordPress Push Notification for Post and BuddyPress plugin to the latest available version (at least 1.64). Unknown discovered and reported this Broken Access Control vulnerability in WordPress Push Notification for Post and BuddyPress Plugin. A broken access control issue refers to a missing authorization,...

Affected:
up to 1.64
Fixed in:
1.64
Disclosed:
Aug 23, 2023

Push Notification for Post and BuddyPress <= 1.63 - Missing Authorization to Unauthenticated Admin Notice Dismissal

medium

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the PNFPB_icpushadmincallback_callback function hooked via a nopriv AJAX action in versions up to, and including, 1.63. This makes it possible for unauthenticated at...

CVSS:
5.3
Affected:
up to 1.64
Fixed in:
1.64
Disclosed:
Aug 22, 2023

Push Notification for Post and BuddyPress [push-notification-for-post-and-buddypress] < 1.64

unknown

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the PNFPB_icpushadmincallback_callback function hooked via a nopriv AJAX action in versions up to, and including, 1.63. This makes it possible for unauthenticated at...

Affected:
up to 1.64
Fixed in:
1.64
Disclosed:
Aug 22, 2023

Push Notification for Post and BuddyPress [push-notification-for-post-and-buddypress] < 1.9.4

unknown
Affected:
up to 1.9.4
Fixed in:
1.9.4

CVE-2024-6159 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database