CVE-2026-93896

CVE-2026-93896 published: The WPFront Notification Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 3.5.1. This is due to the debug-log output path (write_debug_logs) reflecting the raw value of $_SERVER['REQUEST_URI'] throug...

View full NVD advisory → ← Back to CVE watch