Resources /
WordPress Plugins /
Onesignal Free Web Push Notifications
PLUGIN SECURITY
Is Onesignal Free Web Push Notifications safe?
Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.
What this plugin does
- Slug:
onesignal-free-web-push-notifications
- Author: OneSignal Push Notifications
- 70000+ active installs
- 86/100 rating (360 reviews on wordpress.org)
- 5256488 all-time downloads
- On WordPress.org since 2015-05-01
chrome pushdesktop notificationsmobile notificationspush notificationpush notifications
Maintenance status
- Last updated: 2026-07-02 10:18pm GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 7.4+
Known vulnerabilities
3 known CVEs on file for Onesignal Free Web Push Notifications.
Reported between 2019 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-3155
|
OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 3.8.1 |
Missing Authorization |
Low
3.1
|
< 3.8.1
|
3.8.1 |
2026-04-15 |
—
|
|
CVE-2025-13950
|
OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 3.6.2 |
Missing Authorization |
Medium
5.3
|
< 3.6.2
|
3.6.2 |
2025-12-15 |
—
|
|
CVE-2019-15827
|
OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 1.17.8 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
5.4
|
< 1.17.8
|
1.17.8 |
2019-07-18 |
—
|
CVE-2026-3155
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete OneSignal metadata for arbitrary posts.
Source:
CVE.org
CVE-2025-13950
The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due to the plugin processing POST requests without verifying user capabilities or nonces. This makes it possible for unauthenticated attackers to overwrite the OneSignal App ID, REST API key, and notification behavior via direct POST requests.
Source:
CVE.org
CVE-2019-15827
The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.
Source:
CVE.org
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.