CVE-2026-87762
Received Received - Intake

Unauthenticated Stored XSS in Adwised Web Push Notification WordPress Plugin

Vulnerability report for CVE-2026-87762, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: WPScan

Description

The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Unknown Adwised Web Push Notification 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated stored cross-site scripting (XSS) flaw in the Adwised Web Push Notification WordPress plugin versions up to 2.5.7. It occurs because the plugin lacks proper authorization checks on state-changing operations and uses a weak secret comparison that can be bypassed if the secret key was never set. This allows attackers to inject arbitrary JavaScript code that executes in the browsers of all site visitors.

Detection Guidance

Check if the Adwised Web Push Notification WordPress plugin version is 2.5.7 or lower. Inspect JavaScript code for unauthorized script injections in plugin files or database entries. Monitor browser console logs for unexpected script executions on site pages.

Impact Analysis

Attackers can exploit this to inject malicious JavaScript into your WordPress site, which would run in the browsers of every visitor. This could lead to theft of cookies, session hijacking, defacement of your site, or spreading malware to your users. Since no authentication is required, any visitor could be affected without warning.

Compliance Impact

This vulnerability could lead to data breaches by allowing attackers to steal user data or session tokens, violating GDPR and HIPAA requirements for data protection and confidentiality. Affected organizations may face legal penalties, loss of customer trust, and compliance violations due to unauthorized code execution on their websites.

Mitigation Strategies

Update the Adwised Web Push Notification plugin to the latest version if available. If no update exists, consider disabling the plugin temporarily. Review and remove any suspicious JavaScript code from plugin settings or database. Set a strong secret key if the plugin allows it.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87762. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart