MEDIUM
syammohanm
CVE published 2026-10-03
CVE-2026-93896
The WPFront Notification Bar plugin for WordPress has a Reflected Cross-Site Scripting vulnerability in versions up to 3.5.1. This vulnerability allows unauthenticated attackers to inject web scripts into pages if they can trick a user into clicking a specially crafted link. The vulnerability is caused by the plugin's debug-log output path reflecting the raw value of $_SERVER['REQUEST_URI'] through vprint [truncated]