Stored Cross-Site Scripting Vulnerability in Webpushr Push Notifications for WordPress
CVE-2026-9729
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 July 2026
What is CVE-2026-9729?
The Webpushr Push Notifications plugin for WordPress is susceptible to stored cross-site scripting due to inadequate input sanitization in the saving functionality and lack of output escaping in the notification display function. This vulnerability permits authenticated users with contributor-level access or higher to inject malicious scripts, which can execute when other users interact with affected pages. As a result, attackers can manipulate site content or redirect users, posing significant security threats.
Affected Version(s)
Web Push Notifications β Webpushr 0 <= 4.39.0