CVE-2024-31928 MEDIUM

CVE-2024-31928: WordPress Top Bar plugin <= 3.0.5 - Cross Site Scripting (XSS) vulnerability

Vendor Wp Darko
Product Top Bar
Weakness CWE-79 · XSS
Published April 11, 2024
Last update April 28, 2026

CVSS base score

5.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

What the vulnerability does

01Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Darko Top Bar allows Stored XSS.This issue affects Top Bar: from n/a through 3.0.5.

Explanation of Vulnerability in Simple Terms

02Summary

Top Bar versions up to 3.0.5 contain a stored cross-site scripting (XSS) vulnerability. An authenticated administrator can inject malicious scripts into the top bar configuration. When other users or administrators view pages with the affected top bar, the injected script executes in their browser, potentially compromising their session or stealing sensitive data.

What an attacker can do

03Attacker Capabilities

Run malicious JavaScript in the browsers of site visitors and administrators.

Potential impact on your site

04Site Impact

Administrators with malicious intent can inject scripts that steal session tokens, deface content, or compromise other admin accounts.

Conditions required to exploit

05Prerequisites

Attacker must have administrator privileges and a victim must view a page containing the affected top bar.

Key dates

06Disclosure timeline

April 11, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE