Push Notification for Post and BuddyPress <= 3.23 - Unauthenticated Insecure Direct Object Reference to Push Subscription Registration for Arbitrary Users via User ID Parameters

Medium 6.5 CWE-639Fixed in 3.24
ID
WPSEC-2026-0752
Plugin
Push Notification for Post and BuddyPress (push-notification-for-post-and-buddypress)
Affected
all versions before 3.24
Remediation
Update to 3.24 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness
CWE-639
Usage
Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
Attack surface
Push Notification for Post and BuddyPress on WPSec AttackSurface
Fix released
Published

Description

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference via the device subscription AJAX handler (icpushcallback) in all versions up to, and including, 3.23, due to the handler trusting a user-supplied user ID ('webtoapp_userid', 'progressier_external_id', 'onesignal_externalid', 'onesignal_get_subscriptionoptions_id' or 'progressier_get_subscriptionoptions_id') instead of the ID of the current user. This makes it possible for unauthenticated attackers, using a nonce exposed on the public site, to register a device token of their choice under an arbitrary user account, such as an administrator, and receive that user's targeted push notifications (for example BuddyPress private message notifications sent through WebToApp). It also lets them mark arbitrary users as subscribed and read the notification subscription preferences stored for any user.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0