WP Clinic
Log in Sign up

PLUGIN SECURITY

Is Custom Banners safe?

Known vulnerabilities, PHP compatibility and safer alternatives for the Custom Banners WordPress plugin — checked against WP Clinic's local security database.

What this plugin does

  • Slug: custom-banners

Maintenance status

Known vulnerabilities

4 known CVEs on file for Custom Banners. Reported between 2014 and 2024.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-8799 Custom Banners [custom-banners] <= 3.3 (unfixed + closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 6.1 < 3.3 3.3 2024-09-30
CVE-2021-4342 Custom Banners [custom-banners] < 3.3 (closed) Unknown < 3.3 3.3 2023-06-07
CVE-2021-4407 Custom Banners [custom-banners] < 3.3 (closed) Cross-Site Request Forgery (CSRF) Medium 4.3 < 3.3 3.3 2021-03-01
Custom Banners [custom-banners] < 3.3 (closed) Unknown < 3.3 3.3 2021-02-18
CVE-2014-4724 Custom Banners [custom-banners] < 2.1 (closed) Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Unknown < 2.1 2.1 2014-06-29
Custom Banners [custom-banners] < 3.3 (closed) Unknown < 3.3 3.3
Custom Banners [custom-banners] < 3.3 (closed) Unknown < 3.3 3.3

CVE-2024-8799

The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Source: CVE.org

CVE-2021-4342

CVE split into individual CVE IDs for each software record.

Source: CVE.org

CVE-2021-4407

The Custom Banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.2.2 This is due to missing or incorrect nonce validation on the saveCustomFields() function. This makes it possible for unauthenticated attackers to save custom fields via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Source: CVE.org

Custom Banners [custom-banners] < 3.3 (closed)

Cross-Site Request Forgery (CSRF) vulnerability found by WPScan Team in WordPress Custom Banners plugin (versions <= 3.2.2).

Source: Patchstack

CVE-2014-4724

Cross-site scripting (XSS) vulnerability in the Custom Banners plugin before 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the custom_banners_registered_name parameter to wp-admin/options.php.

Source: Wordfence

Custom Banners [custom-banners] < 3.3 (closed)

The plugin did not properly check the CSRF nonce in the saveCustomFields() method, which could allow attackers to make a logged in user with the edit_post capability to save custom fields in a post. Numerous sanitisation fixes were also added to v3.3

Source: WPScan

Custom Banners [custom-banners] < 3.3 (closed)

Over 70 plugins and themes were vulnerable to Cross-Site Request Forgery due to improperly implemented nonce protection that could be bypassed.

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.