Impact
An improper neutralization of input during web page generation in the gingerplugins Notification Bar plugin allows a stored cross‑site scripting vulnerability. The flaw permits an attacker to inject malicious script code that is persisted and served to any visitor of the affected WordPress site. This stored XSS enables arbitrary script execution from the compromised site. The weakness corresponds to CWE‑79.
Affected Systems
All installations of gingerplugins Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme with a plugin version up to and including 1.1 are affected. This includes any WordPress site that has not upgraded beyond version 1.1 when the vulnerability was introduced.
Risk and Exploitability
The CVSS base score of 5.9 indicates moderate severity. The EPSS score is below 1 %, suggesting that actual exploitation has not been widely observed, and the vulnerability is not listed in the CISA KEV catalog. The stored nature of the flaw means that an attacker who can submit content (e.g., via the plugin’s admin interface or a privileged user) can embed malicious code that will run in all browsers that view the impacted page. The likely attack vector is the plugin’s input fields that are not properly sanitized, allowing an attacker to inject persisting script tags.
OpenCVE Enrichment
EUVD