Junglewise Threat Intelligence

CVE-2026-52698: Syed Balkhi PushEngage sensitive data exposure in WordPress plugin

CVE-2026-52698 · Severity: high · CVSS 7.4 · Published 2026-06-17

Executive brief

A vulnerability in the PushEngage WordPress plugin, which is used for web push notifications and eCommerce automation, allows users with low-level 'Subscriber' accounts to access sensitive information. This exposure could lead to the disclosure of private data that should only be accessible to administrators, potentially compromising customer privacy or providing a foothold for further attacks. Organizations using this plugin should update to the latest version to protect their data and operations.

Technical details

The PushEngage plugin for WordPress is vulnerable to sensitive data exposure (CWE-201) in versions up to and including 4.2.3. The flaw occurs when the application inserts sensitive information into data sent over the network to users who lack the proper authorization. An attacker with a minimum privilege level of 'Subscriber' can exploit this to view sensitive system or user information. The vulnerability has been assigned a CVSS score of 7.4, reflecting its potential for partial impact on confidentiality, integrity, and availability. A fix is available in version 4.2.4.

Affected products

  • Syed Balkhi PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2.3

Timeline

  • 2026-05-15: other: Reported by Jakub Herman
  • 2026-06-10: advisory: Patchstack advisory published
  • 2026-06-17: disclosed: NVD publication date

References