WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in Welcome Bar

Increase engagement and drive specific offers to the visitors coming from a specific traffic source. As seen on BetaList and ProductHunt.

3Reported vulnerabilities
4.4Highest CVSS score
2.2.0Latest version
10+Active installs

What to do now

Update Welcome Bar to 2.2.0 or later. 3 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 3, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2025-32129 Medium 4.4 0.4% 2.1.0 and earlier 2.2.0 April 4, 2025
WF-82a26836-44fc-47cf-ad09-bd3d264e8635 Medium 4.3 2.0.3 and earlier 2.0.4 March 31, 2023
WF-98730677-200b-4b1a-8568-7af8b2b0e94b Medium 4.3 2.0.3 and earlier 2.0.4 March 31, 2023

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.