Custom Banners <= 3.3 - Reflected Cross-Site Scripting
medium
The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...
- CVSS:
- 6.1
- Affected:
- up to 3.3
- Fix:
- No patched version reported
- Disclosed:
- Sep 30, 2024
CVE-2024-8799 on NVD →
Custom Banners <= 3.2.2 - Cross-Site Request Forgery Bypass
medium
The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted the...
- CVSS:
- 4.3
- Affected:
- up to 3.2.2
- Fixed in:
- 3.3
- Disclosed:
- Mar 1, 2021
CVE-2021-4407 on NVD →
Custom Banners < 2.1 - Cross-Site Scripting
high
Cross-site scripting (XSS) vulnerability in the Custom Banners plugin before 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_banners_registered_name parameter to wp-admin/options.php.
- CVSS:
- 7.1
- Affected:
- up to 2.1
- Fixed in:
- 2.1
- Disclosed:
- Jun 29, 2014
CVE-2014-4724 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database