Impact
Improper neutralization of user input results in a stored cross‑site scripting vulnerability within the WP Notification Bell plugin. When an attacker submits data that is later rendered without escaping, arbitrary JavaScript can execute in the browsers of visitors who view the affected page. This allows theft of session tokens, account hijacking, or defacement of content. The weakness corresponds to CWE‑79.
Affected Systems
The vulnerability affects the WordPress WP Notification Bell plug‑in, version 1.4.6 and older. The plug‑in is distributed under the wpdever vendor. WordPress sites that have not upgraded beyond 1.4.6 are potentially impacted.
Risk and Exploitability
The CVSS base score of 5.9 indicates a moderate severity, while the EPSS score of less than 1 % suggests a very low probability of observed exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can trigger the stored XSS by injecting script payloads into plugin configuration fields that are persisted and later displayed. Successful exploitation would allow the attacker to run client‑side code with the permissions of the end user, potentially leading to data theft or defacement.
OpenCVE Enrichment
EUVD