PT-2026-82474 · WordPress · Push Notification For Post/Buddypress
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Push Notification for Post and BuddyPress versions prior to 3.21
Description
Broken Access Control allows users with Subscriber privileges to perform unauthorized actions within the plugin.
Recommendations
Update Push Notification for Post and BuddyPress to a version newer than 3.20.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Push Notification For Post/Buddypress