CVE-2025-15481
Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure
MEDIUM 5.3EPSS 0.2%
The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
- Affected
- Notification Bar for WordPress
- CVSS v3.1 WPSCAN
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS
- 0.19% chance of exploitation in the next 30 days, 8th percentile
- Published
- 2026-09-02