
CVE-2026-0816 The All push notification for WP plugin for WordPress is vulnerable to time-based SQL Injection via the 'delete_id' parameter in all versions up to, and including, 1.5.… https://www.cve.org/CVERecord?id=CVE-2026-0816
Post summary
The All Push Notification for WP plugin is vulnerable to time‑based SQL Injection through the 'delete_id' parameter in versions up to 1.5. No patch, PoC, or active exploitation information is provided.

