[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZ4-FgPIGYWvaskluLSU9J8ud0H678cFtwDg-NGa7bu8":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":11,"severity":12,"cvss_score":13,"cvss_vector":14,"vuln_type":15,"published_date":16,"updated_date":17,"references":18,"days_to_patch":20},"CVE-2023-5620","webpushr-missing-authorization-to-unauthenticated-stored-cross-site-scripting","Webpushr \u003C= 4.34.0 - Missing Authorization to Unauthenticated Stored Cross-Site Scripting","The Web Push Notifications – Webpushr plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpp_save_settings function in all versions up to, and including, 4.34.0. This makes it possible for unauthenticated attackers to modify plugin options and inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","webpushr-web-push-notifications",null,"\u003C=4.34.0","4.35.0","high",7.2,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Missing Authorization","2023-11-06 00:00:00","2024-01-22 19:56:02",[19],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F7e092d67-ab81-4366-824c-cfb240ba3042?source=api-prod",78]