WPFront Notification Bar [wpfront-notification-bar] < 3.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront Notification Bar allows Stored XSS.This issue affects WPFront Notification Bar: from n/a through 3.3.2.
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- Mar 27, 2024
CVE-2024-29819 on NVD →
WPFront Notification Bar <= 3.3.2 - Authenticated (Editor+) Stored Cross-Site Scripting
medium
The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbit...
- CVSS:
- 6.4
- Affected:
- up to 3.3.2
- Fixed in:
- 3.4
- Disclosed:
- Mar 25, 2024
CVE-2024-29819 on NVD →
WPFront Notification Bar [wpfront-notification-bar] < 3.4
unknown
[en] The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...
- Affected:
- up to 3.4
- Fixed in:
- 3.4
- Disclosed:
- Jan 25, 2024
CVE-2024-0625 on NVD →
WPFront Notification Bar <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via wpfront-notification-bar-options[custom_class]
medium
The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...
- CVSS:
- 4.4
- Affected:
- up to 3.3.2
- Fixed in:
- 3.4
- Disclosed:
- Jan 24, 2024
CVE-2024-0625 on NVD →
WPFront Notification Bar [wpfront-notification-bar] < 2.1.0.08087
unknown
[en] The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- Affected:
- up to 2.1.0.08087
- Fixed in:
- 2.1.0.08087
- Disclosed:
- Sep 6, 2021
CVE-2021-24601 on NVD →
WPFront Notification Bar [wpfront-notification-bar] < 2.0.0.07176
unknown
[en] The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
- Affected:
- up to 2.0.0.07176
- Fixed in:
- 2.0.0.07176
- Disclosed:
- Aug 16, 2021
CVE-2021-24518 on NVD →
WPFront Notification Bar <= 2.0.0 - Authenticated Stored Cross-Site Scripting
medium
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 5.4
- Affected:
- up to 2.0.0
- Fixed in:
- 2.1.0
- Disclosed:
- Aug 9, 2021
CVE-2021-24601 on NVD →
WPFront Notification Bar [wpfront-notification-bar] < 2.1.0.08087
unknown
Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Siddheshwar Vishwambhar Mane in WordPress WPFront Notification Bar plugin (versions <= 2.1.0).
- Affected:
- up to 2.1.0.08087
- Fixed in:
- 2.1.0.08087
- Disclosed:
- Aug 9, 2021
WPFront Notification Bar [wpfront-notification-bar] < 2.0.0
unknown
Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress WPFront Notification Bar plugin (versions <= 1.9.2).
- Affected:
- up to 2.0.0
- Fixed in:
- 2.0.0
- Disclosed:
- Jul 16, 2021
WPFront Notification Bar <= 1.9.2 - Authenticated Stored Cross-Site Scripting
medium
The WPFront Notification Bar WordPress plugin before 2.0.0 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue
- CVSS:
- 4.8
- Affected:
- up to 1.9.2
- Fixed in:
- 2.0.0
- Disclosed:
- Jul 11, 2021
CVE-2021-24518 on NVD →
WPFront Notification Bar [wpfront-notification-bar] < 1.9.2
unknown
Stored Cross-Site Scripting (XSS) vulnerability discovered by Swapnil Subhash Bodekar in WordPress WPFront Notification Bar plugin (versions <= 1.9.1).
- Affected:
- up to 1.9.2
- Fixed in:
- 1.9.2
- Disclosed:
- Jul 11, 2021
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database