OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-87762 (CVSS 8.8)

NVD · officialPublished Oct 11, 2026Risk 37/100EPSS 0.2%

The Adwised Web Push Notification WordPress plugin through 2.5.7 does not have authorisation checks on several state-changing operations, and the secret comparison it uses instead can be bypassed on installations where the secret key has never been set, allowing unauthenticated users to store arbitrary JavaScript that is executed in the browser of every site visitor.

CVSS
8.8
AV:NetworkAC:LowPR:NoneUI:RequiredC:HighI:HighA:High

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source