Unauthorized Data Modification in OneSignal Web Push Notifications Plugin for WordPress
CVE-2025-13950
5.3MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 15 December 2025
What is CVE-2025-13950?
The OneSignal β Web Push Notifications plugin for WordPress contains a vulnerability that allows unauthorized data modifications. This issue arises from a lack of proper capability checks within the settings handling functionality, affecting all versions up to and including 3.6.1. The plugin processes POST requests without adequate verification of user capabilities or nonces, enabling unauthenticated attackers to overwrite key settings such as the OneSignal App ID, REST API key, and notification behavior through direct POST requests.
Affected Version(s)
OneSignal β Web Push Notifications * <= 3.6.1