The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
We have discovered 1,177 live websites that are affected by CVE-2025-1672.
Product | |
Category | Wordpress Plugins |
Vulnerable Domains | 1,177 live websites (91.95% of Notibar install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 13 versions ( 92.86% of all versions) |
![]() | 584 websites |
![]() | 101 websites |
![]() | 67 websites |
![]() | 44 websites |
![]() | 35 websites |
![]() | 25 websites |
![]() | 24 websites |
![]() | 23 websites |
![]() | 20 websites |
![]() | 19 websites |
.com | 556 websites |
.org | 90 websites |
.co.uk | 46 websites |
.com.au | 42 websites |
.de | 40 websites |
.ca | 34 websites |
.fr | 24 websites |
.it | 22 websites |
.net | 20 websites |
.nl | 20 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*********.com | ![]() | ***,*** | |
**********.org | ![]() | ***,*** | |
******.nl | ![]() | ***,*** | |
*******************.com | ![]() | ***,*** | |
************.com | ![]() | ***,*** | |
********.com | ![]() | ***,*** | |
***********.com | ![]() | ***,*** | |
*******.com | ![]() | ***,*** | |
**********.com | ![]() | ***,*** | |
***************.com | ![]() | ***,*** |
FAQ