CVE-2024-1660
The Top Bar plugin through version 3.0.4 contains a stored cross-site scripting vulnerability in its administrative settings caused by inadequate sanitization of user input and lack of proper output encoding. Attackers with administrator privileges can inject malicious scripts that will run when other users view affected pages, though this vulnerability only impacts multisite WordPress installations or setups where the unfiltered_html capability has been restricted. The flaw was corrected in version 3.0.5.
Based on public CVE data (MITRE/NVD).