Resources /
WordPress Plugins /
Custom Banners
PLUGIN SECURITY
Is Custom Banners safe?
Known vulnerabilities, PHP compatibility and safer alternatives for the Custom Banners WordPress plugin — checked against WP Clinic's local security database.
What this plugin does
Maintenance status
Known vulnerabilities
4 known CVEs on file for Custom Banners.
Reported between 2014 and 2024.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-8799
|
Custom Banners [custom-banners] <= 3.3 (unfixed + closed) |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Medium
6.1
|
< 3.3
|
3.3 |
2024-09-30 |
—
|
|
CVE-2021-4342
|
Custom Banners [custom-banners] < 3.3 (closed) |
— |
Unknown
|
< 3.3
|
3.3 |
2023-06-07 |
—
|
|
CVE-2021-4407
|
Custom Banners [custom-banners] < 3.3 (closed) |
Cross-Site Request Forgery (CSRF) |
Medium
4.3
|
< 3.3
|
3.3 |
2021-03-01 |
—
|
|
—
|
Custom Banners [custom-banners] < 3.3 (closed) |
— |
Unknown
|
< 3.3
|
3.3 |
2021-02-18 |
—
|
|
CVE-2014-4724
|
Custom Banners [custom-banners] < 2.1 (closed) |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
Unknown
|
< 2.1
|
2.1 |
2014-06-29 |
—
|
|
—
|
Custom Banners [custom-banners] < 3.3 (closed) |
— |
Unknown
|
< 3.3
|
3.3 |
— |
—
|
|
—
|
Custom Banners [custom-banners] < 3.3 (closed) |
— |
Unknown
|
< 3.3
|
3.3 |
— |
—
|
CVE-2024-8799
The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Source:
CVE.org
CVE-2021-4342
CVE split into individual CVE IDs for each software record.
Source:
CVE.org
CVE-2021-4407
The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Source:
CVE.org
Custom Banners [custom-banners] < 3.3 (closed)
Cross-Site Request Forgery (CSRF) vulnerability found by WPScan Team in WordPress Custom Banners plugin (versions <= 3.2.2).
Source:
Patchstack
CVE-2014-4724
Cross-site scripting (XSS) vulnerability in the Custom Banners plugin before 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_banners_registered_name parameter to wp-admin/options.php.
Source:
Wordfence
Custom Banners [custom-banners] < 3.3 (closed)
The plugin did not properly check the CSRF nonce in the saveCustomFields() method, which could allow attackers to make a logged in user with the edit_post capability to save custom fields in a post.
Numerous sanitisation fixes were also added to v3.3
Source:
WPScan
Custom Banners [custom-banners] < 3.3 (closed)
Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.