Cross-site Scripting Vulnerability in Welcome Bar by Data443 Risk Mitigation, Inc.
CVE-2025-32129

5.9MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
4 April 2025

What is CVE-2025-32129?

The Welcome Bar plugin by Data443 Risk Mitigation, Inc. is susceptible to a Stored Cross-site Scripting (XSS) vulnerability, allowing malicious users to inject executable scripts into the web interface. This issue can lead to unauthorized actions and data exposure for users interacting with the affected versions of the plugin. It affects all versions from unspecified up to 2.0.4, posing a significant risk for web administrators using this plugin in their environments.

Affected Version(s)

Welcome Bar 0 <= 2.0.4

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

timomangcut (Patchstack Alliance)
.