CVE-2025-13950OneSignal WordPress推送通知插件存在严重的安全漏洞,攻击者可未经身份验证直接通过POST请求修改插件配置。漏洞源于插件未正确验证用户权限和nonce令牌,导致Settings处理功能缺乏必要的访问控制。
The vulnerability stems from insufficient validation of user permissions and nonce tokens during POST request handling. This allows unauthenticated attackers to modify critical plugin settings through direct requests.