CVE · Medium

CVE-2021-24518 — WPFront Notification Bar [wpfront-notification-bar] < 2.0.0.07176

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24518 WPFront Notification Bar [wpfront-notification-bar] < 2.0.0.07176 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.0.0.07176 2.0.0.07176 2021-07-11

CVE-2021-24518

The WPFront Notification Bar plugin versions before 2.0.0.07176 contain a stored cross-site scripting vulnerability in the Custom CSS setting. An authenticated user with elevated privileges, such as an administrator, can inject malicious JavaScript code through this field because the plugin fails to properly validate or encode the input. This vulnerability persists even when unfiltered_html capabilities are restricted, allowing the attacker to execute arbitrary scripts that affect all site visitors viewing the notification bar.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.