Description
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete OneSignal metadata for arbitrary posts.
Problem types
Product status
Any version
Timeline
| 2026-02-24: | Vendor Notified |
| 2026-04-15: | Disclosed |
Credits
Muhammad Sharief
References
www.wordfence.com/...-ba10-4876-b91c-78657afc67d1?source=cve
plugins.trac.wordpress.org/...al-free-web-push-notifications