A vulnerability was found in Webpushr Push Notifications Plugin up to 4.39.0 on WordPress and classified as problematic. This vulnerability affects the function
save_send_notification_flag/wpp_notification_box. Such manipulation of the argument webpushr_notification_title/webpushr_notification_body leads to cross site scripting.
This vulnerability is traded as CVE-2026-9729. The attack may be launched remotely. There is no exploit available.