CVE-2024-11012
Published
CVSS v3
6.3
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT
Description
The The Notibar – Notification Bar for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via njt_nofi_text AJAX action in all versions up to, and including, 2.1.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
<p>Multiple notification bars with React-powered customizer, live preview, smart scheduling, and per-bar display rules.</p>
<p>This plugin lets you create and manage <strong>multiple notification bars</strong> at once. Configure each bar independently (content, style, devices, display pages, close behaviour) all inside the native WordPress Customizer with <strong>instant live preview</strong>.</p>
<p>The <strong>Dismiss</strong> button supports three modes: close permanently, collapse/toggle, or disabled.</p>
<p><strong>Per-bar page/post rules</strong> let you show bars on all pages, no pages, or a specific include/exclude list.</p>
<p>🔔 Check out <strong><a href="https://ninjateam.org/notibar-wordpress-notification-bar/?utm_source=wp-org&utm_medium=notibar" rel="nofollow ugc">Notibar Pro – Notification Bar for WordPress</a></strong></p>
<p>Notibar seamlessly integrates with your existing WordPress theme, ensuring a cohesive look and feel. It has integrated clear and compelling call-to-action buttons to drive user engagement and conversions.</p>
<p>📌 <strong><a href="https://ninjateam.gitbook.io/notibar/how-it-works/customize-section/display-settings" rel="nofollow ugc">Documentation</a></strong></p>
<h3>⚡️ FEATURES</h3>
<p><strong>This alert banner is built to optimize appearance and drive a positive impact on your WordPress website traffic and conversions:</strong></p>
<ul>
<li>Designed with <strong>clean UI</strong> & modern style</li>
<li><strong>Schedule</strong> the date and time to go live</li>
<li>Display in absolute or fixed positioning</li>
<li>Custom color, text, click-to-action</li>
<li>Various notice bar <strong>style presets</strong></li>
<li>Set text container width and alignment</li>
<li>Actions for <strong>Dismiss</strong> button: disable, toggle, close for good</li>
<li>WYSIWYG visual banner editor with <strong>live preview</strong></li>
<li>Display on all pages/posts or specific page/post ID</li>
<li>Add different content for mobile devices</li>
<li>Drag and drop to reorder announcement bars</li>
<li>One click to duplicate a bar template</li>
<li>Export/Import for a quick migration</li>
<li>100% mobile-responsive</li>
</ul>
<h3>🚀 TYPICAL USE CASES</h3>
<p><strong>These are good ideas on how to exploit the Notification Bar plugin:</strong></p>
<ul>
<li>Important announcements</li>
<li>Technical notices</li>
<li>Time-sensitive appeals for donation or CTA</li>
<li>Subscription increase</li>
<li>Terms or operational changes</li>
<li>Privacy policy acknowledgments</li>
<li>Maintenance messages</li>
<li>Service outage or resource shortage</li>
<li>Seasonal offers or promotions on <a href="https://wpbrandy.com/starter-sites/" rel="nofollow ugc">WooCommerce stores</a></li>
<li>Driving traffic to other sites</li>
</ul>
<p>Notibar is ideal for you to promote upcoming events, new blog posts, product launches, or special offers with ease.</p>
<p>Did you know? You can even capture email leads by offering incentives and integrating with your email marketing provider.</p>
<h3>🎉 Supported Themes and Plugins</h3>
<p>We have done extra work to ensure complete compatibility with all themes, page builders and other popular plugins.</p>
<h3>📝 Documentation and Support</h3>
<p>If you’re having issues, do let us know and we’ll try to help you out.<br />
You can always reach us at <a href="http://ninjateam.org/support" rel="nofollow ugc">Ninja Team Support Center</a>.</p>
<h3>♥️ Like this Top Bar Alert Plugin?</h3>
<ul>
<li>Rate us 5⭐ stars on <a href="https://wordpress.org/support/plugin/notibar/reviews/?filter=5#new-post" rel="ugc">WordPress.org</a></li>
<li>Check out these tutorials to <a href="https://yaycommerce.com/category/woocommerce-tutorials/?utm_source=wp-org&utm_medium=notibar" rel="nofollow ugc">create successful WooCommerce stores</a></li>
</ul>