Junglewise Threat Intelligence

CVE-2026-81279: Push Notification for Post and BuddyPress broken access control

CVE-2026-81279 · Severity: medium · CVSS 5.4 · Published 2026-08-27

Executive brief

A WordPress plugin that manages push notifications for posts and BuddyPress community features contains an access control vulnerability in versions up to 3.20. Subscriber-level users can bypass permission checks to access or perform actions they should not be allowed to, such as viewing data belonging to other users or triggering notifications inappropriately.

Technical details

The plugin fails to properly enforce authorization checks on push notification operations, allowing subscribers (low-privilege users) to access or manipulate notification-related features without proper permission validation. The vulnerability is rooted in insufficient access control checks in the plugin's functionality that handles push notifications tied to BuddyPress and post data. Exploitation requires a valid subscriber account on the WordPress site. An attacker with subscriber privileges can read sensitive data or perform unauthorized actions related to push notifications and user content. The issue is resolved in version 3.21 and later.

Affected products

  • Muralidharan Ramasamy Push Notification for Post and BuddyPress <= 3.20

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Patch available in version 3.21

References