plugin

Wpfront Notification Bar Vulnerabilities

11 known security issues reported for the Wpfront Notification Bar WordPress plugin. Most recent disclosed Mar 27, 2024.

4 medium

Running Wpfront Notification Bar on your site? Check whether your installed version is affected.

Scan your site free

WPFront Notification Bar [wpfront-notification-bar] < 3.4

unknown

[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront Notification Bar allows Stored XSS.This issue affects WPFront Notification Bar: from n/a through 3.3.2.

Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
Mar 27, 2024

CVE-2024-29819 on NVD →

WPFront Notification Bar <= 3.3.2 - Authenticated (Editor+) Stored Cross-Site Scripting

medium

The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with editor-level permissions and above, to inject arbit...

CVSS:
6.4
Affected:
up to 3.3.2
Fixed in:
3.4
Disclosed:
Mar 25, 2024

CVE-2024-29819 on NVD →

WPFront Notification Bar [wpfront-notification-bar] < 3.4

unknown

[en] The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attacker...

Affected:
up to 3.4
Fixed in:
3.4
Disclosed:
Jan 25, 2024

CVE-2024-0625 on NVD →

WPFront Notification Bar <= 3.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting via wpfront-notification-bar-options[custom_class]

medium

The WPFront Notification Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpfront-notification-bar-options[custom_class]’ parameter in all versions up to, and including, 3.3.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi...

CVSS:
4.4
Affected:
up to 3.3.2
Fixed in:
3.4
Disclosed:
Jan 24, 2024

CVE-2024-0625 on NVD →

WPFront Notification Bar [wpfront-notification-bar] < 2.1.0.08087

unknown

[en] The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

Affected:
up to 2.1.0.08087
Fixed in:
2.1.0.08087
Disclosed:
Sep 6, 2021

CVE-2021-24601 on NVD →

WPFront Notification Bar [wpfront-notification-bar] < 2.0.0.07176

unknown

[en] The WPFront Notification Bar WordPress plugin before 2.0.0.07176 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

Affected:
up to 2.0.0.07176
Fixed in:
2.0.0.07176
Disclosed:
Aug 16, 2021

CVE-2021-24518 on NVD →

WPFront Notification Bar <= 2.0.0 - Authenticated Stored Cross-Site Scripting

medium

The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

CVSS:
5.4
Affected:
up to 2.0.0
Fixed in:
2.1.0
Disclosed:
Aug 9, 2021

CVE-2021-24601 on NVD →

WPFront Notification Bar [wpfront-notification-bar] < 2.1.0.08087

unknown

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Siddheshwar Vishwambhar Mane in WordPress WPFront Notification Bar plugin (versions <= 2.1.0).

Affected:
up to 2.1.0.08087
Fixed in:
2.1.0.08087
Disclosed:
Aug 9, 2021

WPFront Notification Bar [wpfront-notification-bar] < 2.0.0

unknown

Stored Cross-Site Scripting (XSS) vulnerability discovered in WordPress WPFront Notification Bar plugin (versions <= 1.9.2).

Affected:
up to 2.0.0
Fixed in:
2.0.0
Disclosed:
Jul 16, 2021

WPFront Notification Bar <= 1.9.2 - Authenticated Stored Cross-Site Scripting

medium

The WPFront Notification Bar WordPress plugin before 2.0.0 does not sanitise or escape its Custom CSS setting, allowing high privilege users such as admin to set XSS payload in it even when the unfiltered_html capability is disallowed, leading to an authenticated Stored Cross-Site Scripting issue

CVSS:
4.8
Affected:
up to 1.9.2
Fixed in:
2.0.0
Disclosed:
Jul 11, 2021

CVE-2021-24518 on NVD →

WPFront Notification Bar [wpfront-notification-bar] < 1.9.2

unknown

Stored Cross-Site Scripting (XSS) vulnerability discovered by Swapnil Subhash Bodekar in WordPress WPFront Notification Bar plugin (versions <= 1.9.1).

Affected:
up to 1.9.2
Fixed in:
1.9.2
Disclosed:
Jul 11, 2021

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database