Push Notification for Post and BuddyPress <= 3.23 - Unauthenticated Insecure Direct Object Reference to Push Subscription Registration for Arbitrary Users via User ID Parameters
- ID
- WPSEC-2026-0752
- Plugin
- Push Notification for Post and BuddyPress (push-notification-for-post-and-buddypress)
- Affected
- all versions before 3.24
- Remediation
- Update to 3.24 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Weakness
- CWE-639
- Usage
- Plugin Low · Affected versions Low among sites WPSec scans, 2026-10-10
- Attack surface
- Push Notification for Post and BuddyPress on WPSec AttackSurface
- Fix released
- Published
Description
The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference via the device subscription AJAX handler (icpushcallback) in all versions up to, and including, 3.23, due to the handler trusting a user-supplied user ID ('webtoapp_userid', 'progressier_external_id', 'onesignal_externalid', 'onesignal_get_subscriptionoptions_id' or 'progressier_get_subscriptionoptions_id') instead of the ID of the current user. This makes it possible for unauthenticated attackers, using a nonce exposed on the public site, to register a device token of their choice under an arbitrary user account, such as an administrator, and receive that user's targeted push notifications (for example BuddyPress private message notifications sent through WebToApp). It also lets them mark arbitrary users as subscribed and read the notification subscription preferences stored for any user.
References
- https://wpsec.com/vuln/WPSEC-2026-0752/
- https://plugins.svn.wordpress.org/push-notification-for-post-and-buddypress/tags/3.24/
- https://wordpress.org/plugins/push-notification-for-post-and-buddypress/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS