Reflected Cross-Site Scripting Vulnerability in WPFront Notification Bar by WordPress
CVE-2026-93896

6.1MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 October 2026

What is CVE-2026-93896?

The WPFront Notification Bar plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit reflected cross-site scripting. This is due to the direct output of raw request URI data in a script block via vprintf(), without any proper sanitization or escaping. Consequently, attackers can potentially insert malicious web scripts into visited pages, deceiving users into executing harmful actions if they interact with crafted links. This poses a significant threat to user security and website integrity.

Affected Version(s)

WPFront Notification Bar 0 <= 3.5.1

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan
.