plugin

Dw Promobar Vulnerabilities

1 known security issue reported for the Dw Promobar WordPress plugin. Most recent disclosed Jul 19, 2022.

1 medium

Running Dw Promobar on your site? Check whether your installed version is affected.

Scan your site free

DW Promobar <= 1.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The DW Promobar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dwpb_bar_text' parameter in versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with administrative level capabilities to inject arbi...

CVSS:
5.5
Affected:
up to 1.0.4
Fix:
No patched version reported
Disclosed:
Jul 19, 2022

CVE-2022-2423 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database