WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Onesignal Free Web Push Notifications safe?

Increase engagement and drive more repeat traffic to your WordPress site with push notifications. Now a WordPress VIP Gold Partner.

What this plugin does

  • Slug: onesignal-free-web-push-notifications
  • Author: OneSignal Push Notifications
  • 70000+ active installs
  • 86/100 rating (360 reviews on wordpress.org)
  • 5256488 all-time downloads
  • On WordPress.org since 2015-05-01

chrome pushdesktop notificationsmobile notificationspush notificationpush notifications

Maintenance status

  • Last updated: 2026-07-02 10:18pm GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4+

Known vulnerabilities

3 known CVEs on file for Onesignal Free Web Push Notifications. Reported between 2019 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-3155 OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 3.8.1 Missing Authorization Low 3.1 < 3.8.1 3.8.1 2026-04-15
CVE-2025-13950 OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 3.6.2 Missing Authorization Medium 5.3 < 3.6.2 3.6.2 2025-12-15
CVE-2019-15827 OneSignal – Web Push Notifications [onesignal-free-web-push-notifications] < 1.17.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 5.4 < 1.17.8 1.17.8 2019-07-18

CVE-2026-3155

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 3.8.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete OneSignal metadata for arbitrary posts.

Source: CVE.org

CVE-2025-13950

The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the settings handling functionality in all versions up to, and including, 3.6.1. This is due to the plugin processing POST requests without verifying user capabilities or nonces. This makes it possible for unauthenticated attackers to overwrite the OneSignal App ID, REST API key, and notification behavior via direct POST requests.

Source: CVE.org

CVE-2019-15827

The onesignal-free-web-push-notifications plugin before 1.17.8 for WordPress has XSS via the subdomain parameter.

Source: CVE.org

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.