PT-2026-63581 · WordPress · Web Push Notifications
CVE-2026-9729
·
Published
2026-07-23
·
Updated
2026-07-23
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Webpushr Push Notifications versions prior to 4.39.1
Description
Stored Cross-Site Scripting occurs when authenticated attackers with contributor-level access or higher inject arbitrary web scripts into pages. This is caused by insufficient input sanitization in the
save send notification flag() function and missing output escaping in the wpp notification box() function, which directly concatenates raw post meta values into HTML attribute and textarea contexts. The issue involves the webpushr notification title and webpushr notification body parameters.Recommendations
Update to a version newer than 4.39.0.
As a temporary workaround, restrict access to the
webpushr notification title and webpushr notification body parameters for users with contributor-level access.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Web Push Notifications