Extension WordPress
Vulnérabilités OneSignal – Web Push Notifications
Cette page rassemble les failles publiées pour OneSignal – Web Push Notifications, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de OneSignal – Web Push Notifications
3 fiches
OneSignal – Web Push Notifications <= 3.8.0 – Missing Authorization to Authenticated (Subscriber+) Post Meta Deletion via 'post_id'
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an…
*-3.8.0
3.8.1
15/04/2026
OneSignal – Web Push Notifications <= 3.6.1 – Missing Authorization to Unauthenticated Plugin Settings Update
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due…
*-3.6.1
3.6.2
15/12/2025
OneSignal Web Push Notifications <=1.17.7 – Stored Cross-Site Scripting
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
*-1.17.7
1.17.8
18/07/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.