First published: Mon Sep 06 2021(Updated: )
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
8degreethemes Notification Bar | <2.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24601 is a vulnerability in the WPFront Notification Bar WordPress plugin that allows high privilege users to perform Cross-Site Scripting attacks.
The severity of CVE-2021-24601 is rated as medium with a CVSS score of 5.4.
The vulnerability CVE-2021-24601 can allow high privilege users to perform Cross-Site Scripting attacks.