CyberRota Analysis
AI-GeneratedThe Notification Bar for WordPress plugin versions up to 1.1.8 contains an unauthenticated CSV export script that allows attackers to access and disclose all stored subscriber email addresses. This vulnerability poses a medium risk, as it can lead to unauthorized access to sensitive user data, potentially facilitating spam or phishing attacks. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of data exposure.
CVE
CVE-2025-15481
Severity
MEDIUM
CVSS
5.3
EPSS
0.19%
WordPress
Original NVD Description
The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.