WordPress security by component
SKT Skill Bar
Plugin description
SKT Skill Bar displays animated skill bars and progress indicators in WordPress content.
SKT Skill Bar (skt-skill-bar) is a WordPress plugin with 5 published CVE records in this archive. The latest tracked vulnerability was published Aug 05, 2026; the highest published CVSS base score is 6.5.
Plugin slug:
skt-skill-barLatest vulnerability
CVE-2026-6972: SKT Skill Bar chart_size shortcode attribute permits stored XSS
SKT Skill Bar through 2.6 lets a Contributor store an attacker-controlled chart_size attribute in the skillwrapper shortcode. The plugin concatenates that value directly into an inline style block without sufficient sanitization or escaping, allowing stored JavaScript to execute whenever a visitor opens the affected page. The CNA does not disclose the rendering function or required breakout encoding.
| Safe version |
|
||
|---|---|---|---|
| Aug 05, 2026 |
CVE-2026-6972
SKT Skill Bar chart_size shortcode attribute permits stored XSS
SKT Skill Bar through 2.6 lets a Contributor store an attacker-controlled chart_size attribute in the skillwrapper shortcode. The plugin concatenates that value directly into an inline style block without sufficient sanitization or escaping, allowing stored JavaScript to execute whenever a visitor opens the affected page. The CNA does not disclose the rendering function or required breakout encoding.
|
> 2.6 |
CVE6.4
NVDPending
|
| Nov 21, 2025 |
CVE-2025-66090
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| May 07, 2025 |
CVE-2025-47482
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Apr 15, 2025 |
CVE-2025-26880
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|
| Jul 20, 2024 |
CVE-2024-38698
SKT Skill Bar: Cross-site scripting
SKT Skill Bar is affected by cross-site scripting. Exposure depends on how the affected operation is made reachable by the site. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The public source does not disclose the vulnerable endpoint, action, parameter or function, so the precise input path remains unknown.
|
See mitigation notes |
CVE6.5
NVDPending
|