plugin

Splash Header Vulnerabilities

1 known security issue reported for the Splash Header WordPress plugin. Most recent disclosed Jul 29, 2021.

1 medium

Running Splash Header on your site? Check whether your installed version is affected.

Scan your site free

Splash Header < 1.20.8 - Stored Cross-Site Scripting

medium

The Splash Header WordPress plugin before 1.20.8 doesn't sanitise and escape some of its settings while outputting them in the admin dashboard, leading to an authenticated Stored Cross-Site Scripting issue.

CVSS:
5.5
Affected:
up to 1.20.8
Fixed in:
1.20.8
Disclosed:
Jul 29, 2021

CVE-2021-24587 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database