cleantalk
Vulnerabilities and Security Researches

Vulnerabilities and security researches forall-push-notification all-push-notification

Direction: descending
Apr 16, 2026

All push notification for WP # CVE-2026-0816

CVE, Research URL

CVE-2026-0816

Date
Feb 04, 2026
Research Description
The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' parameter in all versions up to, and including, 1.5.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.
Affected versions
max 1.5.3.
Status
vulnerable
Apr 19, 2025

All push notification for WP # CVE-2025-32546

CVE, Research URL

CVE-2025-32546

Date
Apr 17, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.
Affected versions
max 1.5.3.
Status
vulnerable
Apr 11, 2025

All push notification for WP # CVE-2025-32547

CVE, Research URL

CVE-2025-32547

Date
Apr 09, 2025
Research Description
Cross-Site Request Forgery (CSRF) vulnerability in gtlwpdev All push notification for WP allows Blind SQL Injection. This issue affects All push notification for WP: from n/a through 1.5.3.
Affected versions
max 1.5.3.
Status
vulnerable
Feb 19, 2025

All push notification for WP # CVE-2025-25092

CVE, Research URL

CVE-2025-25092

Date
Mar 03, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gtlwpdev All push notification for WP allows Reflected XSS. This issue affects All push notification for WP: from n/a through 1.5.3.
Affected versions
max 1.5.3.
Status
vulnerable
Feb 05, 2025

All push notification for WP # CVE-2025-25073

CVE, Research URL

CVE-2025-25073

Date
Feb 07, 2025
Research Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vasilis Triantafyllou Easy WP Tiles allows Stored XSS. This issue affects Easy WP Tiles: from n/a through 1.
Affected versions
max 1.5.3.
Status
vulnerable