Orbisius Simple Notice
Orbisius Simple Notice has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Orbisius Simple Notice has a vendor fix available, so running the current release closes it.
All of these findings were reported by Pham Van Tam. Orbisius Simple Notice is installed on roughly 100 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 6.7.7.
CVE-2025-24634Orbisius Simple Notice <= 1.1.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records
Orbisius Simple Notice
Author
Svetoslav Marinov
This plugin allows you to show a simple notice to alert your users about server maintenance, new product launches etc. Features / Benefits Enter text an the message will be shown to your users. For logged in users the notice will be shifted by 28px (because WP admin bar is obstructing the notice) Rich text editor to enter notice text Use nice color pickers to select the colors for notice text, background and link color (if any). Supports text and HTML The notice can be shown on top of all content or to push the content down You can choose to show the notice on all pages/posts or on the home page only Optionally show a close button. When a notice is closed/dismissed it won’t be shown again until the message is changed or more than 2 days have passed. Change the font size of the box Demo Live demo powered by WPDemo.net https://wpdemo.net/try/plugin/orbisius-simple-notice Support The support is handled here: https://github.com/orbisius/orbisius-simple-notice/issues Please do NOT use the WordPress forums or other places to seek support as we might not see it on time. Author Svetoslav Marinov (Slavi) | Custom Plugin, Web & SaaS app Development by Orbisius.com
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C