Impact
The WPFront Notification Bar plugin renders the raw REQUEST_URI value inside a <script> tag without proper escaping. An unauthenticated attacker can trigger this by visiting a specially crafted URL, causing arbitrary JavaScript to execute in the victim’s browser. This enables session hijacking, cookie theft, defacement, or other client‑side abuse.
Affected Systems
WordPress installations running WPFront Notification Bar version 3.5.1 or earlier are vulnerable. No specific sub‑versions are listed beyond all releases up to 3.5.1.
Risk and Exploitability
With a CVSS score of 6.1, the vulnerability presents moderate potential for exploitation. The EPSS value is not available and the issue is not yet listed in the CISA KEV catalog. An attacker can affect any user who follows a malicious link, as the vulnerability does not require authentication or privileged access. The impact is limited to client‑side execution, but the consequences can be substantial for compromised sessions.
OpenCVE Enrichment