{
 "id": "WPSEC-2026-0752",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0752/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0752/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0752/index.md",
 "title": "Push Notification for Post and BuddyPress <= 3.23 - Unauthenticated Insecure Direct Object Reference to Push Subscription Registration for Arbitrary Users via User ID Parameters",
 "description": "The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference via the device subscription AJAX handler (icpushcallback) in all versions up to, and including, 3.23, due to the handler trusting a user-supplied user ID ('webtoapp_userid', 'progressier_external_id', 'onesignal_externalid', 'onesignal_get_subscriptionoptions_id' or 'progressier_get_subscriptionoptions_id') instead of the ID of the current user. This makes it possible for unauthenticated attackers, using a nonce exposed on the public site, to register a device token of their choice under an arbitrary user account, such as an administrator, and receive that user's targeted push notifications (for example BuddyPress private message notifications sent through WebToApp). It also lets them mark arbitrary users as subscribed and read the notification subscription preferences stored for any user.",
 "plugin": {
  "slug": "push-notification-for-post-and-buddypress",
  "name": "Push Notification for Post and BuddyPress",
  "full_name": "Push Notification for Post and BuddyPress",
  "wordpress_org": "https://wordpress.org/plugins/push-notification-for-post-and-buddypress/",
  "advisories_url": "https://wpsec.com/vuln/plugin/push-notification-for-post-and-buddypress/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/push-notification-for-post-and-buddypress"
 },
 "type": "IDOR",
 "cwe": [
  "CWE-639"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 6.5,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
  "severity": "Medium"
 },
 "affected": {
  "ranges": [
   {
    "from": null,
    "from_inclusive": true,
    "to": "3.24",
    "to_inclusive": false
   }
  ],
  "text": [
   "all versions before 3.24"
  ]
 },
 "introduced_in": null,
 "fixed_in": "3.24",
 "remediation": "Update to 3.24 or later.",
 "fix_released": "2026-10-09T03:58:16+00:00",
 "published": "2026-10-10T15:41:27+00:00",
 "updated": "2026-10-10T14:54:06.859996+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0752/",
  "https://plugins.svn.wordpress.org/push-notification-for-post-and-buddypress/tags/3.24/",
  "https://wordpress.org/plugins/push-notification-for-post-and-buddypress/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/push-notification-for-post-and-buddypress",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "Low",
  "affected_versions": "Low",
  "as_of": "2026-10-10"
 }
}