vendor:
WPFront Notification Bar
by:
Swapnil Subhash Bodekar
5.5
CVSS
MEDIUM
Stored Cross-Site Scripting (XSS)
79
CWE
Product Name: WPFront Notification Bar
Affected Version From: 1.9.1.04012
Affected Version To: 1.9.1.04012
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows
2021
WordPress Plugin WPFront Notification Bar 1.9.1.04012 – Stored Cross-Site Scripting (XSS)
The vulnerability allows an attacker to store malicious script code in the database, which is then executed when triggered by certain functionality.
Mitigation:
Update to the latest version of the WordPress plugin or apply a patch if available. Avoid using user input directly without proper validation and sanitization.