Push notification for Mobile and Web app
Push notification for Mobile and Web app has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.3, and the most serious one scores 5.3 out of 10.
The most common weakness is Missing Authorization, behind 1 of the records (100%).
The one issue recorded for Push notification for Mobile and Web app has a vendor fix available, so running the current release closes it.
All of these findings were reported by ch4r0n. Push notification for Mobile and Web app is installed on roughly 400 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.6.7.
CVE-2025-48127Push notification for Mobile and Web app <= 2.0.3 - Missing Authorization
Read the full analysisVulnerability Records

Push notification for Mobile and Web app
Author
App Cheap
Support push notification for mobile and the web app. Demo app Push services support Firebase HTTP V1 Firebase HTTP legacy OneSignal Debug How does it work The Push Notification plugin is built with five part: Trigger: When WordPress action execution (Post saved, Order status changed …) Recipients: One/ More recipients get the notification ( topic, registration ID, role, user, merge tag …) Conditionals: Determine whether notification send Action: The action when the user click to notification on device Merge Tag: That is dynamic information in that context String translation: Replace part of string on title and message Plugin Features Comment Post: Fires immediately after a comment is inserted into the database. Post Type: Fires when a post is transitioned from one status to another. Save Post: Fires once a post has been saved. Order Status Changed: Fires when an order is transitioned from one status to another. Product Status Changed: Fires when a product is transitioned from one status to another. WCFM – Direct Messaging: Fires when vendor receive a message. BuddyPress: Fires Messages message sent, Activity Posted Update, Friends Friendship Accepted, Friends Friendship Requested, Groups Posted Update, Groups Send Invites
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C