Cross-Site Scripting Issue in OneSignal Free Web Push Notifications by WordPress
CVE-2019-15827

5.4MEDIUM

Key Information:

Vendor

Wordpress

Vendor
CVE Published:
30 August 2019

What is CVE-2019-15827?

The OneSignal Free Web Push Notifications plugin for WordPress, prior to version 1.17.8, contains a Cross-Site Scripting (XSS) vulnerability that arises from improper handling of the 'subdomain' parameter. This security flaw can be exploited by attackers to inject malicious scripts into the web application, allowing them to execute arbitrary code in the context of the user’s browser. This could lead to data theft, session hijacking, and other malicious activities aimed at compromising the security of the WordPress site.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.