CVE Database /
CVE-2025-13950
CVE · Medium
CVE-2025-13950 — OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 3.6.2
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-13950
|
OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 3.6.2 |
Missing Authorization |
Medium
5.3
|
< 3.6.2
|
3.6.2 |
2025-12-15 |
—
|
CVE-2025-13950
The OneSignal Web Push Notifications WordPress plugin has a security flaw that allows unauthorized changes to its settings. All versions of the plugin up to 3.6.1 are affected because they don't properly check user permissions before processing certain types of data updates. As a result, an attacker can make changes to key settings like the App ID and notification behavior without needing any authentication.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings