sonalsinha21 Vulnerabilities and Affected Products
Vulnerabilities associated with SKT Skill Bar.
Products
Clear product- SKT Blocks6 vulnerabilities
- SKT Addons for Elementor4 vulnerabilities
- SKT Skill Bar4 vulnerabilities
- SKT Page Builder3 vulnerabilities
- Posterity2 vulnerabilities
- Recover abandoned cart for WooCommerce2 vulnerabilities
- SKT Blocks – Gutenberg based Page Builder2 vulnerabilities
- Admire Extra1 vulnerability
- Barter1 vulnerability
- Bicycleshop1 vulnerability
- SKT Donation1 vulnerability
- SKT PayPal for WooCommerce1 vulnerability
- SKT Templates – 100% Free Templates for Elementor & Gutenberg1 vulnerability
- SKT Templates – Elementor & Gutenberg templates1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-6972MEDIUM | SKT Skill Bar <= 2.6 - Authenticated (Contributor+) Stored Cross-Site ScriptingThe SKT Skill Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `chart_size` attribute of the `skillwrapper` shortcode in all versions up to, and including, 2.6. This is due to insufficient input sanitization and output escaping on the `chart_size` attribute, which is concatenated directly into an inline `<style>` block. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execu… CWE-79Aug 5, 2026 | CVSS6.4v3.1 | EPSS0.201% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-66090MEDIUM | WordPress SKT Skill Bar plugin <= 2.5 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows DOM-Based XSS.This issue affects SKT Skill Bar: from n/a through <= 2.5. CWE-79Nov 21, 2025 | CVSS6.5v3.1 | EPSS0.151% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-47482MEDIUM | WordPress SKT Skill Bar plugin <= 2.4 - Cross Site Scripting (XSS) VulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows Stored XSS.This issue affects SKT Skill Bar: from n/a through <= 2.4. CWE-79May 7, 2025 | CVSS6.5v3.1 | EPSS0.245% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26880MEDIUM | WordPress SKT Skill Bar plugin <= 2.3 - Cross Site Scripting (XSS) vulnerabilityImproper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT Skill Bar skt-skill-bar allows Stored XSS.This issue affects SKT Skill Bar: from n/a through <= 2.3. CWE-79Apr 15, 2025 | CVSS6.5v3.1 | EPSS0.252% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |