CVE Database /
CVE-2022-2629
CVE · Medium
CVE-2022-2629 — Top Bar [top-bar] < 3.0.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2022-2629
|
Top Bar [top-bar] < 3.0.4 |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
4.8
|
< 3.0.4
|
3.0.4 |
2022-09-08 |
—
|
CVE-2022-2629
The Top Bar plugin for WordPress versions before 3.0.4 contains a stored cross-site scripting vulnerability in the tpbr_message, tpbr_btn_text, tpbr_btn_url, and tpbr_color parameters. Administrators can inject malicious scripts through these fields, which then execute in the browsers of users who visit affected pages. An attacker with admin credentials would need to convince a user to interact with a crafted link to trigger the stored payload.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings