CVE-2024-6159: Pnfpb Push Notification For Post And Buddypress

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

The Push Notification for Post and BuddyPress WordPress plugin before 1.9.4 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection

Affected products

  • Pnfpb Push Notification For Post And Buddypress: before 1.9.4 (fixed in 1.9.4)

Published 2025-05-15. Last modified 2026-06-17.