HIGH
Ryan Sutana
CVE published 2026-01-08
CVE-2025-68891
A Cross-site Scripting (XSS) vulnerability exists in the WP App Bar plugin for WordPress, affecting versions from n/a through 1.5. This issue allows for Reflected XSS attacks. Defenders should assess exposure and prioritize patching or mitigation to prevent exploitation. The vulnerability arises from improper neutralization of input during web page generation, potentially leading to unauthorized script ex [truncated]