CVE-2024-6159: Pnfpb Push Notification For Post And Buddypress
Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.
The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
Affected products
- Pnfpb Push Notification For Post And Buddypress: before 1.9.4 (fixed in 1.9.4)
Published 2025-05-15. Last modified 2026-06-17.