CVE-2025-15380
Last modified
CVE-2025-15380 is a high-severity vulnerability rated 7.2/10 on the CVSS scale. The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to insufficient input sanitization and output escaping when processing preview data. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
The NotificationX – FOMO, Live Sales Notification, WooCommerce Sales Popup, GDPR, Social Proof, Announcement Banner & Floating Notification Bar plugin for WordPress is vulnerable to DOM-Based Cross-Site Scripting via the 'nx-preview' POST parameter in all versions up to, and including, 3.2.0. This is due to insufficient input sanitization and output escaping when processing preview data. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute when a user visits a malicious page that auto-submits a form to the vulnerable site.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-15380?
How severe is CVE-2025-15380?
How do I fix CVE-2025-15380?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-15375A flaw has been found in EyouCMS up to 1.7.7. The impacted e…8.8
- CVE-2025-15376The Stopwords for comments plugin for WordPress is vulnerabl…4.3
- CVE-2025-15377The Sosh Share Buttons plugin for WordPress is vulnerable to…4.3
- CVE-2025-15378The AJS Footnotes plugin for WordPress is vulnerable to Stor…7.2
- CVE-2025-15379A command injection vulnerability exists in MLflow's model s…9.8
- CVE-2025-1538A vulnerability classified as critical was found in D-Link D…8.8
- CVE-2025-15381In the latest version of mlflow/mlflow, when the `basic-auth…7.1
- CVE-2025-15382A heap buffer over-read vulnerability exists in the wolfSSH_…8.1
- CVE-2025-15385Insufficient Verification of Data Authenticity vulnerability…9.8
- CVE-2025-15386The Responsive Lightbox & Gallery WordPress plugin before 2.…8.8
- CVE-2025-15387VPN Firewall developed by QNO Technology has a Insufficient …8.8
- CVE-2025-15388VPN Firewall developed by QNO Technology has an OS Command I…8.8
Are you affected by CVE-2025-15380?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
