Impact
The Notif Bell plugin contains an improper neutralization of input during web page generation, resulting in a stored XSS vulnerability as described by CWE‑79. Malicious payloads submitted via the plugin can be saved and later executed in any browser that renders the affected page, enabling attackers to steal session cookies, perform defacement, or inject additional scripts that compromise the integrity or confidentiality of the site and its users.
Affected Systems
This flaw affects the WordPress Notif Bell plugin developed by MarMar8x, including all released versions up to and including 0.9.8. WordPress sites that have installed any of these plugin versions are potentially vulnerable.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate level of risk. The EPSS score of < 1 % suggests that exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the plugin’s input interfaces, where an attacker with access to submit data to the plugin can store malicious payloads that will be rendered to other users. Successful exploitation can lead to client‑side script execution and the attendant threats such as cookie theft and session hijacking.
OpenCVE Enrichment
EUVD