Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Notice Bar notice-bar allows Stored XSS.This issue affects Notice Bar: from n/a through <= 3.1.3.
Published: 2025-08-20
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Local administrators can create a notice bar entry containing malicious code that is then stored in the database and rendered in the site’s pages without input sanitization. When visitors load the affected site, the embedded script executes in their browsers. Based on the description, it is inferred that an attacker could steal authentication cookies, deface content or redirect users, but the CVE does not explicitly state these outcomes. The flaw is a classic stored XSS due to improper neutralization of input during web page generation, classified as CWE‑79.

Affected Systems

The vulnerability is present in the WEN Solutions Notice Bar plugin for WordPress versions from the initial release up to and including 3.1.3. Any WordPress installation utilizing a version of the plugin within this range and allowing editors or administrators to input notice content is susceptible.

Risk and Exploitability

With a CVSS score of 6.5, the flaw falls into the medium severity range. The EPSS score of less than 1% indicates a very low current probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an authenticated administrator creating or editing a notice entry that contains malicious script; the stored payload is then delivered to all site visitors. This inference assumes that the notice content is displayed without sanitization. Since the script runs in the context of the site’s domain, any visitor to the page could be affected, potentially compromising session data or allowing content defacement.

Generated by OpenCVE AI on April 30, 2026 at 15:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official patch or update released by WEN Solutions that fixes the XSS vulnerability once it becomes available.
  • If an upgrade is not immediately feasible, edit or delete any existing notice entries that may contain malicious scripts and replace them with plain text, or temporarily disable the plugin from the WordPress admin interface.
  • Remove the plugin completely if the site’s notice functionality is not required, or replace it with a validated alternative that sanitizes user input.

Generated by OpenCVE AI on April 30, 2026 at 15:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25300 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Notice Bar allows Stored XSS. This issue affects Notice Bar: from n/a through 3.1.3.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Notice Bar allows Stored XSS. This issue affects Notice Bar: from n/a through 3.1.3. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Notice Bar notice-bar allows Stored XSS.This issue affects Notice Bar: from n/a through <= 3.1.3.
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wensolutions
Wensolutions notice Bar
Wordpress
Wordpress wordpress
Vendors & Products Wensolutions
Wensolutions notice Bar
Wordpress
Wordpress wordpress

Wed, 20 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Notice Bar allows Stored XSS. This issue affects Notice Bar: from n/a through 3.1.3.
Title WordPress Notice Bar Plugin <= 3.1.3 - Cross Site Scripting (XSS) Vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Wensolutions Notice Bar
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:02.901Z

Reserved: 2025-06-04T15:43:46.346Z

Link: CVE-2025-49389

cve-icon Vulnrichment

Updated: 2025-08-20T13:40:47.147Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:34.370

Modified: 2026-04-23T15:31:34.960

Link: CVE-2025-49389

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T15:45:40Z

Weaknesses