plugin

Custom Banners Vulnerabilities

3 known security issues reported for the Custom Banners WordPress plugin. Most recent disclosed Sep 30, 2024.

1 high 2 medium

Running Custom Banners on your site? Check whether your installed version is affected.

Scan your site free

Custom Banners <= 3.3 - Reflected Cross-Site Scripting

medium

The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they ca...

CVSS:
6.1
Affected:
up to 3.3
Fix:
No patched version reported
Disclosed:
Sep 30, 2024

CVE-2024-8799 on NVD →

Custom Banners <= 3.2.2 - Cross-Site Request Forgery Bypass

medium

The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted the...

CVSS:
4.3
Affected:
up to 3.2.2
Fixed in:
3.3
Disclosed:
Mar 1, 2021

CVE-2021-4407 on NVD →

Custom Banners < 2.1 - Cross-Site Scripting

high

Cross-site scripting (XSS) vulnerability in the Custom Banners plugin before 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_banners_registered_name parameter to wp-admin/options.php.

CVSS:
7.1
Affected:
up to 2.1
Fixed in:
2.1
Disclosed:
Jun 29, 2014

CVE-2014-4724 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database