Cross-site Scripting Vulnerability in Pushe Web Push Notification by Pusheco
CVE-2025-58873
5.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 September 2025
What is CVE-2025-58873?
A cross-site scripting (XSS) vulnerability exists in the Pushe Web Push Notification plugin, allowing attackers to inject malicious scripts. This affects versions from n/a through 0.5.0, leading to potential data theft and compromised user accounts.
Affected Version(s)
Pushe Web Push Notification <= 0.5.0