Cross-Site Scripting Vulnerability in WEN Solutions Notice Bar Plugin
CVE-2025-49389

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
20 August 2025

What is CVE-2025-49389?

The WEN Solutions Notice Bar plugin is vulnerable to a stored Cross-Site Scripting (XSS) issue caused by improper input neutralization during web page generation. An attacker could exploit this vulnerability to inject malicious scripts, which are then stored and executed in users' browsers when they access the affected web page. This vulnerability affects versions of the Notice Bar plugin from n/a up to 3.1.3, allowing for potential unauthorized actions and data manipulation if left unaddressed.

Affected Version(s)

Notice Bar <= 3.1.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.
CVE-2025-49389 : Cross-Site Scripting Vulnerability in WEN Solutions Notice Bar Plugin