Missing Authorization in App Cheap Push Notification for Mobile and Web App
CVE-2025-48127
6.5MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 16 May 2025
What is CVE-2025-48127?
A missing authorization vulnerability exists in the App Cheap Push Notification for Mobile and Web app, allowing unauthorized users to exploit incorrectly configured access control security levels. This security flaw can lead to unauthorized access, enabling malicious actors to perform actions without proper authentication. Affected versions include all prior to 2.0.3, requiring immediate attention for those using older releases to mitigate potential risks.
Affected Version(s)
Push notification for Mobile and Web app <= 2.0.3