The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
Metrics
Affected Vendors & Products
References
History
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. | |
| Title | Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: WPScan
Published: 2026-09-02T14:25:47.075Z
Updated: 2026-09-02T14:57:36.291Z
Reserved: 2026-01-07T14:47:37.670Z
Link: CVE-2025-15481
Updated: 2026-09-02T14:43:18.376Z
Status : Deferred
Published: 2026-09-02T15:17:36.320
Modified: 2026-09-03T17:50:37.690
Link: CVE-2025-15481
No data.