# Push Notification for Post and BuddyPress <= 3.23 - Unauthenticated Insecure Direct Object Reference to Push Subscription Registration for Arbitrary Users via User ID Parameters

- **ID:** WPSEC-2026-0752
- **Plugin:** Push Notification for Post and BuddyPress (`push-notification-for-post-and-buddypress`), https://wordpress.org/plugins/push-notification-for-post-and-buddypress/
- **Affected versions:** all versions before 3.24
- **Fixed in:** 3.24 (Update to 3.24 or later.)
- **Severity:** Medium 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
- **Weakness:** CWE-639
- **Usage among sites WPSec scans:** plugin Low, affected versions Low (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/push-notification-for-post-and-buddypress
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0752/

## Description

The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Insecure Direct Object Reference via the device subscription AJAX handler (icpushcallback) in all versions up to, and including, 3.23, due to the handler trusting a user-supplied user ID ('webtoapp_userid', 'progressier_external_id', 'onesignal_externalid', 'onesignal_get_subscriptionoptions_id' or 'progressier_get_subscriptionoptions_id') instead of the ID of the current user. This makes it possible for unauthenticated attackers, using a nonce exposed on the public site, to register a device token of their choice under an arbitrary user account, such as an administrator, and receive that user's targeted push notifications (for example BuddyPress private message notifications sent through WebToApp). It also lets them mark arbitrary users as subscribed and read the notification subscription preferences stored for any user.

## References

- https://wpsec.com/vuln/WPSEC-2026-0752/
- https://plugins.svn.wordpress.org/push-notification-for-post-and-buddypress/tags/3.24/
- https://wordpress.org/plugins/push-notification-for-post-and-buddypress/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0752/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
