Smartarget Message Bar
Smartarget Message Bar has one disclosed vulnerability in the WordSec catalog, all reported in 2024; it remains unpatched as of September 2026. Their average CVSS score is 4.4, and the most serious one scores 4.4 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Smartarget Message Bar has no published fix yet, which makes virtual patching the only reliable mitigation. The oldest unresolved one dates back to 2024.
All of these findings were reported by Rayhan Ramdhany Hanaputra. The current release is tested up to WordPress 7.0.0.
CVE-2024-35646Smartarget Message Bar <= 1.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Smartarget Message Bar
Author
Erez Hadas-Sonnenschein
The best way to inform users! Do you want to keep your customers engaged by offering them promotions and discounts? Do you want to keep them informed with new business updates and special events? Adding a Message Bar to your website is the most effective way of doing this. Smartarget Message Bar allows you to communicate any message that you want, even multiple messages, in a few minutes. Smartarget Message Bar Pro Features: Pro version overcomes your limitations with lite version of Smartarget Message Bar. Smartarget Message Bar PRO Plugin Features Apps visibility on all pages No Smartarget label BUY Smartarget Message Bar Pro Features : Buy Now
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C