Unauthorized Data Modification in OneSignal Web Push Notifications Plugin for WordPress
CVE-2025-13950

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
15 December 2025

What is CVE-2025-13950?

The OneSignal – Web Push Notifications plugin for WordPress contains a vulnerability that allows unauthorized data modifications. This issue arises from a lack of proper capability checks within the settings handling functionality, affecting all versions up to and including 3.6.1. The plugin processes POST requests without adequate verification of user capabilities or nonces, enabling unauthenticated attackers to overwrite key settings such as the OneSignal App ID, REST API key, and notification behavior through direct POST requests.

Affected Version(s)

OneSignal – Web Push Notifications * <= 3.6.1

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcin Dudek
.
CVE-2025-13950 : Unauthorized Data Modification in OneSignal Web Push Notifications Plugin for WordPress