What the vulnerability does
01Description
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syam Mohan WPFront Notification Bar allows Stored XSS.This issue affects WPFront Notification Bar: from n/a through 3.3.2.
Explanation of Vulnerability in Simple Terms
02Summary
WPFront Notification Bar versions up to 3.3.2 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator with high privileges can inject malicious scripts into notification bar settings. When other users view pages with the notification bar, the injected script executes in their browsers, potentially stealing session data or performing actions on their behalf. The vulnerability requires administrator access and user interaction to exploit.
What an attacker can do
03Attacker Capabilities
Inject malicious scripts that execute in visitors' browsers when they view the notification bar.
Potential impact on your site
04Site Impact
Compromised admin accounts can inject malicious code affecting all site visitors; visitor sessions and data at risk.
Conditions required to exploit
05Prerequisites
Administrator account access; victim must view a page displaying the notification bar.
Key dates
06Disclosure timeline
March 27, 2024
CVE published
April 28, 2026
Record updated