CVE-2026-93896
Received Received - Intake

Reflected Cross-Site Scripting in WPFront Notification Bar Plugin

Vulnerability report for CVE-2026-93896, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-03

Last updated on: 2026-10-03

Assigner: Wordfence

Description

The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) reflecting the raw value of $_SERVER['REQUEST_URI'] through vprintf() directly inside a <script> block emitted on wp_footer, without any sanitization or escaping (see the 'Current URL is "%s"' log entry produced by the URL-text display filter in the filter() method). This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a specially crafted link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-03
Last Modified
2026-10-03
Generated
2026-10-03
AI Q&A
2026-10-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpfront notification_bar to 3.5.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WPFront Notification Bar WordPress plugin up to version 3.5.1 has a reflected Cross-Site Scripting (XSS) vulnerability. It occurs because the plugin outputs the raw REQUEST_URI server value into a JavaScript block without sanitization. Attackers can exploit this by tricking users into clicking a malicious link, which executes arbitrary scripts in their browser.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the WPFront Notification Bar plugin version 3.5.1 or lower. Check for reflected XSS by reviewing debug logs for raw REQUEST_URI values in script blocks. Manually test by appending malicious scripts to URLs and observing if they execute.

Impact Analysis

An attacker could steal session cookies, perform actions on your behalf, or redirect you to phishing sites. Since no authentication is required, any user visiting a crafted link may be affected. The impact includes account takeovers, data theft, or malware delivery.

Compliance Impact

This XSS flaw could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality requirements. For HIPAA, it may expose protected health information. Compliance failures could result in fines or legal penalties due to inadequate security controls.

Mitigation Strategies

Immediately update the WPFront Notification Bar plugin to the latest patched version. If no patch exists, disable or remove the plugin. Implement input validation for REQUEST_URI and sanitize outputs in scripts. Monitor for unusual activity or unauthorized script execution.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93896. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart