SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2025-15481

MEDIUM · CVSS 5.3 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Notification Bar for WordPress plugin versions up to 1.1.8 contains an unauthenticated CSV export script that allows attackers to access and disclose all stored subscriber email addresses. This vulnerability poses a medium risk, as it can lead to unauthorized access to sensitive user data, potentially facilitating spam or phishing attacks. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of data exposure.

CVE
CVE-2025-15481
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress

Original NVD Description

The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.