Cross-Site Scripting Issue in OneSignal Free Web Push Notifications by WordPress
CVE-2019-15827
5.4MEDIUM
Key Information:
- Vendor
Wordpress
- Vendor
- CVE Published:
- 30 August 2019
What is CVE-2019-15827?
The OneSignal Free Web Push Notifications plugin for WordPress, prior to version 1.17.8, contains a Cross-Site Scripting (XSS) vulnerability that arises from improper handling of the 'subdomain' parameter. This security flaw can be exploited by attackers to inject malicious scripts into the web application, allowing them to execute arbitrary code in the context of the user’s browser. This could lead to data theft, session hijacking, and other malicious activities aimed at compromising the security of the WordPress site.