Impact
The Simple Banner WordPress plugin contains a stored cross‑site scripting flaw that permits an authenticated administrator to inject arbitrary scripts through the 'pro_version_activation_code' field. The malicious code is saved in the database and rendered whenever the banner is displayed, allowing the attacker to execute scripts in all users’ browsers, potentially leading to credential theft, defacement or forced redirects.
Affected Systems
This vulnerability targets the Simple Banner plugin (rpetersen29:Simple Banner – Easily add multiple Banners/Bars/Notifications/Announcements to the top or bottom of your website) used on WordPress multisite installations running version 3.0.10 or earlier, and where the unfiltered_html capability has been disabled. Only users with administrator or higher privileges can exploit the flaw.
Risk and Exploitability
The CVSS score of 4.4 categorises the risk as moderate when the attacker holds privileged access. An EPSS score of less than 1% reflects a low chance of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to authenticate to the WordPress admin interface and submit a malicious payload via the pro_version_activation_code control, after which all visitors to pages displaying the banner would run the injected scripts.
OpenCVE Enrichment