Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gingerplugins Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme allows Stored XSS. This issue affects Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme: from n/a through 1.1.
CVE ID: CVE-2025-31610
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.9
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
Vendor: gingerplugins
Product: Notification Bar, Sticky Notification Bar, Sticky Welcome Bar for any theme
EPSS Score: 0.03% (probability of being exploited)
EPSS Percentile: 8.12% (scored less or equal to compared to others)
EPSS Date: 2025-04-21 (when was this score calculated)