Webpushr provides a web-push notification platform that enables websites to deliver push messages to users, a service sitting at the intersection of browser APIs and server-side messaging where input-handling flaws are consequential. Its observed vulnerability signal centers on web application layer weaknesses, particularly cross-site request forgery and cross-site scripting issues that can compromise message integrity and user interaction flows. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Webpushr over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-35041HIGH Cross-Site Request Forgery (CSRF) vulnerability leading to Local File Inclusion (LF) in Webpushr Web Push Notifications Web Push Notifications – Webpushr plugin <= 4.34.0 versions. | Nov 13, 2023 | 8.8 | 25 | NO | NO |
CVE-2023-5620MEDIUM The Web Push Notifications WordPress plugin before 4.35.0 does not prevent visitors on the site from changing some of the plugin options, some of which may be used to conduct Store | Nov 27, 2023 | 5.4 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Webpushr.
Media articles that mention a CVE ID that affects a product developed by Webpushr — matched by CVE ID, not by vendor name.