PT-2026-104547 · WordPress · Wpfront Notification Bar

·

CVE-2026-93896

·

Published

2026-10-03

·

Updated

2026-10-03

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WPFront Notification Bar versions prior to 3.5.2
Description Reflected Cross-Site Scripting occurs when the write debug logs debug-log output path reflects the raw value of the $ SERVER['REQUEST URI'] variable through the vprintf() function within a <script> block emitted on wp footer. This happens without proper sanitization or escaping in the filter() method. Unauthenticated attackers can exploit this by tricking a user into clicking a specially crafted link to inject and execute arbitrary web scripts.
Recommendations Update WPFront Notification Bar to version 3.5.2 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93896

Affected Products

Wpfront Notification Bar