Input validation vulnerability in WP Firebase Push Notification 1.2.0

The WP Firebase Push Notification plugin for WordPress has a security issue that can be exploited by hackers. This issue is present in all versions up to and including 1.2.0. The problem is that the plugin does not properly check for a security code, known as a nonce, when using the wfpn_broadcast_notification_message() function. This means that attackers who are not logged in can send out fake notifications if they can convince the website’s administrator to click on a malicious link.

Detected in:

WP Firebase Push Notification open vulnerable versions: >= * <= 1.2.0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.