Input validation vulnerability in Announcement & Notification Banner – Bulletin 3.5.2

The Announcement & Notification Banner – Bulletin plugin for WordPress has a security vulnerability in versions 3.5.1 and earlier. This vulnerability allows people with a subscriber level permission (or higher) to inject malicious web scripts into pages that can be executed when someone visits the page. This is due to the plugin not properly sanitizing and escaping inputs.

Detected in:

Announcement & Notification Banner – Bulletin open vulnerable versions: >= * <= 3.5.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.