CVE · Medium

CVE-2022-0446 — Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 2.12.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-0446 Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website [simple-banner] < 2.12.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.12.0 2.12.0 2022-07-26

CVE-2022-0446

The Simple Banner plugin versions before 2.12.0 contains a cross-site scripting vulnerability in the "Simple Banner Text" settings field due to insufficient sanitization of user input. Administrators and other high-privilege users can inject malicious scripts through this setting, bypassing protections that restrict the unfiltered_html capability. The vulnerability affects all versions prior to 2.12.0 and is resolved in version 2.12.0 and later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.