Cross-Site Request Forgery in WP Firebase Push Notification Plugin by WordPress
CVE-2025-5924
4.3MEDIUM
What is CVE-2025-5924?
The WP Firebase Push Notification plugin for WordPress has a vulnerability that allows Cross-Site Request Forgery (CSRF), resulting from improper nonce validation in the wfpn_brodcast_notification_message() function. This vulnerability allows unauthenticated attackers to issue broadcast notifications via forged requests, provided they can deceive an administrator into triggering the exploit, such as by clicking a malicious link. All versions of the plugin up to and including version 1.2.0 are affected, making it crucial for users to apply necessary updates and implement additional security measures.