CVE · Medium

CVE-2022-2629 — Top Bar [top-bar] < 3.0.4

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-2629 Top Bar [top-bar] < 3.0.4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 3.0.4 3.0.4 2022-09-08

CVE-2022-2629

The Top Bar plugin for WordPress versions before 3.0.4 contains a stored cross-site scripting vulnerability in the tpbr_message, tpbr_btn_text, tpbr_btn_url, and tpbr_color parameters. Administrators can inject malicious scripts through these fields, which then execute in the browsers of users who visit affected pages. An attacker with admin credentials would need to convince a user to interact with a crafted link to trigger the stored payload.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.