Simple Banner <= 3.0.10 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pro_version_activation_code' parameter in all versions up to, and including, 3.0.10 due to insufficient input sanitization and...
- CVSS:
- 4.4
- Affected:
- up to 3.0.10
- Fixed in:
- 3.1.0
- Disclosed:
- Oct 21, 2025
CVE-2025-12033 on NVD →
Simple Banner <= 3.0.4 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.5 due to insufficient input sanitization and output escaping. This makes it...
- CVSS:
- 4.4
- Affected:
- up to 3.0.4
- Fixed in:
- 3.0.5
- Disclosed:
- Apr 3, 2025
CVE-2024-13898 on NVD →
Simple Banner <= 3.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.3 due to insufficient input sanitization and output escaping. This makes it...
- CVSS:
- 4.4
- Affected:
- up to 3.0.3
- Fixed in:
- 3.0.4
- Disclosed:
- Mar 3, 2025
CVE-2024-12769 on NVD →
Simple Banner <= 2.11.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Simple Banner WordPress plugin before 2.12.0 does not properly sanitize its "Simple Banner Text" Settings allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 2.11.0
- Fixed in:
- 2.12.0
- Disclosed:
- Jul 26, 2022
CVE-2022-0446 on NVD →
Simple Banner <= 2.11.0 - Authenticated Stored Cross-Site Scripting
medium
The Simple Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `pro_version_activation_code` parameter in versions up to, and including, 2.11.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, including those without administrat...
- CVSS:
- 6.4
- Affected:
- up to 2.11.0
- Fixed in:
- 2.12.0
- Disclosed:
- Jul 22, 2022
CVE-2022-2515 on NVD →
Simple Banner <= 2.10.3 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The Simple Banner WordPress plugin before 2.10.4 does not sanitise and escape one of its settings, allowing high privilege users such as admin to use Cross-Site Scripting payload even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.5
- Affected:
- up to 2.10.3
- Fixed in:
- 2.10.4
- Disclosed:
- Jul 26, 2021
CVE-2021-24574 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database