Extension WordPress

Vulnérabilités OneSignal – Web Push Notifications

Cette page rassemble les failles publiées pour OneSignal – Web Push Notifications, leurs plages de versions affectées et les correctifs signalés dans la base locale.

3Vulnérabilités
0Critiques
3Avec correctif
6,4CVSS maximal

Historique de sécurité

CVE et vulnérabilités de OneSignal – Web Push Notifications

3 fiches

CVE-2026-3155 Faible · 3,1
OneSignal – Web Push Notifications

OneSignal – Web Push Notifications <= 3.8.0 – Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id'

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an…

Versions affectées

*-3.8.0

Correctif

3.8.1

Publication

15/04/2026

CVE-2025-13950 Moyenne · 5,3
OneSignal – Web Push Notifications

OneSignal – Web Push Notifications <= 3.6.1 – Missing Authorization to Unauthenticated Plugin Settings Update

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due…

Versions affectées

*-3.6.1

Correctif

3.6.2

Publication

15/12/2025

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités