Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. | |
| Title | Notification Bar for WordPress <= 1.1.8 – Unauthenticated Subscriber Data Disclosure | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-02T14:57:36.291Z
Reserved: 2026-01-07T14:47:37.670Z
Link: CVE-2025-15481
Updated: 2026-09-02T14:43:18.376Z
Status : Received
Published: 2026-09-02T15:17:36.320
Modified: 2026-09-02T15:17:36.320
Link: CVE-2025-15481
No data.
OpenCVE Enrichment
No data.
-
CWE-306
Missing Authentication for Critical Function