CVE-2026-87761
Received Received - Intake

Stored XSS in Adwised Web Push Notification WordPress Plugin

Vulnerability report for CVE-2026-87761, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Adwised Web Push Notification WordPress plugin through 2.5.7 does not perform any capability or nonce check before allowing an authenticated user to overwrite its site-wide configuration, and does not escape those configuration values before printing them inside an inline script block on every front-end page, allowing any authenticated user, such as a subscriber, to perform Stored Cross-Site Scripting attacks against every visitor, including administrators.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Adwised Web Push Notification 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Stored Cross-Site Scripting (XSS) vulnerability in the Adwised Web Push Notification WordPress plugin up to version 2.5.7. It allows authenticated users, even those with basic subscriber access, to inject malicious scripts into the site's configuration. The plugin fails to check user capabilities or validate requests before saving settings and does not escape these settings when displaying them in inline scripts on every front-end page.

Detection Guidance

Check if the Adwised Web Push Notification plugin version is 2.5.7 or lower. Log in as a subscriber or higher and attempt to modify plugin settings to see if changes persist without validation. Inspect front-end pages for inline script blocks containing unescaped configuration values.

Impact Analysis

An attacker could inject malicious scripts that execute for every visitor, including administrators. This could lead to theft of session cookies, account takeovers, or defacement of the website. Even low-privilege users like subscribers can exploit this to affect all site visitors.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection requirements. For HIPAA, it may compromise protected health information if exposed through the injected scripts. Organizations could face fines or penalties for failing to protect user data adequately.

Mitigation Strategies

Update the Adwised Web Push Notification plugin to the latest version immediately. If an update is unavailable, consider disabling the plugin temporarily. Review user roles and restrict subscriber-level access to sensitive functions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87761. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart