Medium severity5.4NVD Advisory· Published Sep 6, 2021· Updated Jun 17, 2026
CVE-2021-24601
CVE-2021-24601
Description
The WPFront Notification Bar WordPress plugin before 2.1.0.08087 does not properly sanitise and escape its settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- WordPress/WPFront Notification Bardescription
- Range: <2.1.0.08087
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/bb437706-a918-4d66-b027-b083ab486074nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.