Sceawere
Vulnerability Detail
CVE-2026-87762UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Adwised Web Push Stored XSS
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- Adwised Web Push Notification
- Attack Type
- CWE-79 Cross-Site Scripting (XSS)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-11T07:17:26.803Z",
"pubdate": "2026-10-11T07:17:26.803Z",
"executiveSummary": "The Adwised Web Push Notification WordPress plugin, in versions up to and including 2.5.7, is susceptible to an unauthenticated Stored Cross-Site Scripting (XSS) vulnerability. The flaw originates from missing authorization checks on critical state-changing functions and a flawed secret key validation mechanism.\nBy bypassing the authentication requirement, an attacker can inject and persist arbitrary JavaScript payloads within the application's configuration. Because this plugin is designed to push notifications to site visitors, the injected malicious scripts are subsequently served and executed within the browsers of all visitors to the affected WordPress site.\nThis vulnerability poses a critical risk to site integrity and visitor security, potentially leading to session hijacking, credential theft, and unauthorized redirects. The attack requires no prior authentication, and the exploitation is trivial on installations where the plugin's secret key remains at its default or unset state. Administrators must prioritize updating the plugin or removing the component if a patched version is unavailable to prevent widespread compromise of site users.",
"technicalDetails": "The vulnerability resides in the core operational logic of the Adwised Web Push Notification plugin (up to version 2.5.7). The root cause is twofold: the absence of proper administrative capability checks (e.g., current_user_can()) on state-changing AJAX or REST API endpoints, and a flawed security implementation regarding secret key verification.\nWhen the plugin is initialized but the secret key is not explicitly set by the administrator, the internal comparison logic for authentication tokens can be bypassed. The code fails to enforce a strict check, allowing unauthenticated requests to reach sensitive internal functions intended only for administrative use. Specifically, the mechanisms responsible for updating plugin settings do not validate the source of the request.\nThe attack flow follows these steps: 1) The attacker identifies the target endpoint responsible for saving plugin settings, which typically includes fields for custom JavaScript or notification parameters. 2) The attacker crafts an HTTP request to this endpoint containing a malicious JavaScript payload. 3) Because the secret key comparison is either unset or bypassable, the backend accepts the request without requiring a valid session or administrator privileges. 4) The plugin saves the malicious payload into the WordPress database as part of the plugin configuration. 5) Once stored, the plugin automatically renders this configuration—including the malicious script—into the front-end source code delivered to site visitors.\nThe impact of this Stored XSS is extensive. Since the injected script executes within the context of the origin site's domain, the attacker gains the ability to perform actions on behalf of the user, access cookies (if not protected by HttpOnly flags), manipulate the DOM, or exfiltrate sensitive data. Given the functionality of a push notification plugin, the payload is frequently and automatically re-executed whenever the site is loaded or specific notification-related events are triggered. This effectively creates a persistent malicious entry point that compromises the security posture of the entire platform and its user base."
}