Pushe Web Push Notification
Pushe Web Push Notification has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Pushe Web Push Notification has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2025.
All of these findings were reported by Que Thanh Tuan - Blue Rock. Pushe Web Push Notification is installed on roughly 20 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 5.3.23.
CVE-2025-58873Pushe Web Push Notification <= 0.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Pushe Web Push Notification
Author
pusheco
This plugin is a free web push notification service for WordPress websites. It allows you to easily add web push notifications to any website. Pushe.co console is only available for Farsi language (English version will come soon). Web push notifications are notifications that can be sent to a user via desktop web and mobile web. Web push notifications are delivered on a user’s desktop or mobile screen anytime they have their browser open. To use this plugin, you should have an account in pushe.co‘s console in console.pushe.co For more information you can check the documentation
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C