← WordPress Vulnerabilities
WordPress security by component

SKT Skill Bar

SKT Skill Bar displays animated skill bars and progress indicators in WordPress content.

SKT Skill Bar (skt-skill-bar) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 6.5.

Plugin slug: skt-skill-bar

CVE-2026-6972: SKT Skill Bar chart_size shortcode attribute permits stored XSS

SKT Skill Bar through 2.6 lets a Contributor store an attacker-controlled chart_size attribute in the skillwrapper shortcode. The plugin concatenates that value directly into an inline style block without sufficient sanitization or escaping, allowing stored JavaScript to execute whenever a visitor opens the affected page. The CNA does not disclose the rendering function or required breakout encoding.

PublishedAug 05, 2026
Known safe version> 2.6
Published vulnerabilities for skt-skill-bar
Safe version
Aug 05, 2026 CVE-2026-6972
SKT Skill Bar chart_size shortcode attribute permits stored XSS
SKT Skill Bar through 2.6 lets a Contributor store an attacker-controlled chart_size attribute in the skillwrapper shortcode. The plugin concatenates that value directly into an inline style block without sufficient sanitization or escaping, allowing stored JavaScript to execute whenever a visitor opens the affected page. The CNA does not disclose the rendering function or required breakout encoding.
> 2.6
CVE6.4
NVDPending
Nov 21, 2025 CVE-2025-66090
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
May 07, 2025 CVE-2025-47482
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Apr 15, 2025 CVE-2025-26880
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending
Jul 20, 2024 CVE-2024-38698
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
See mitigation notes
CVE6.5
NVDPending