CVE Database /
CVE-2021-24518
CVE · Medium
CVE-2021-24518 — WPFront Notification Bar [wpfront-notification-bar] < 2.0.0.07176
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2021-24518
|
WPFront Notification Bar [wpfront-notification-bar] < 2.0.0.07176 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 2.0.0.07176
|
2.0.0.07176 |
2021-07-11 |
—
|
CVE-2021-24518
The WPFront Notification Bar plugin versions before 2.0.0.07176 contain a stored cross-site scripting vulnerability in the Custom CSS setting. An authenticated user with elevated privileges, such as an administrator, can inject malicious JavaScript code through this field because the plugin fails to properly validate or encode the input. This vulnerability persists even when unfiltered_html capabilities are restricted, allowing the attacker to execute arbitrary scripts that affect all site visitors viewing the notification bar.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings