CVE-2025-5924

The WP Firebase Push Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.0. This is due to missing or incorrect nonce validation on the wfpn_brodcast_notification_message() function. This makes it possible for unauthenticated attackers to send broadcast notifications via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Configurations

Configuration 1 (hide)

cpe:2.3:a:skywavesolutions:wp_firebase_push_notification:*:*:*:*:*:wordpress:*:*

History

10 Jul 2025, 15:13

Type Values Removed Values Added
CPE cpe:2.3:a:skywavesolutions:wp_firebase_push_notification:*:*:*:*:*:wordpress:*:*
First Time Skywavesolutions
Skywavesolutions wp Firebase Push Notification
References () https://plugins.trac.wordpress.org/browser/wp-push-notification-firebase/trunk/wp_push_notification_firebase.php#L67 - () https://plugins.trac.wordpress.org/browser/wp-push-notification-firebase/trunk/wp_push_notification_firebase.php#L67 - Product
References () https://www.wordfence.com/threat-intel/vulnerabilities/id/996e0432-e795-4c01-8182-603a47f4f341?source=cve - () https://www.wordfence.com/threat-intel/vulnerabilities/id/996e0432-e795-4c01-8182-603a47f4f341?source=cve - Third Party Advisory

08 Jul 2025, 16:18

Type Values Removed Values Added
Summary
  • (es) El complemento WP Firebase Push Notification para WordPress es vulnerable a Cross-Site Request Forgery en todas las versiones hasta la 1.2.0 incluida. Esto se debe a la falta o a una validación incorrecta de nonce en la función wfpn_brodcast_notification_message(). Esto permite que atacantes no autenticados envíen notificaciones de difusión mediante una solicitud falsificada, siempre que puedan engañar al administrador del sitio para que realice una acción como hacer clic en un enlace.

04 Jul 2025, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-04 03:15

Updated : 2025-07-10 15:13


NVD link : CVE-2025-5924

Mitre link : CVE-2025-5924

CVE.ORG link : CVE-2025-5924


JSON object : View

Products Affected

skywavesolutions

  • wp_firebase_push_notification
CWE
CWE-352

Cross-Site Request Forgery (CSRF)