plugin

Bubble Menu Vulnerabilities

8 known security issues reported for the Bubble Menu WordPress plugin. Most recent disclosed Jan 24, 2025.

4 medium

Running Bubble Menu on your site? Check whether your installed version is affected.

Scan your site free

Bubble Menu – circle floating menu <= 4.0.2 - Cross-Site Request Forgery

medium

The Bubble Menu – circle floating menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.0.2. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request...

CVSS:
4.3
Affected:
up to 4.0.2
Fixed in:
4.0.3
Disclosed:
Jan 24, 2025

CVE-2025-24714 on NVD →

Bubble Menu – Floating Button Menu with Sticky Navigation [bubble-menu] < 4.0.3

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu allows Cross Site Request Forgery. This issue affects Bubble Menu – circle floating menu: from n/a through 4.0.2.

Affected:
up to 4.0.3
Fixed in:
4.0.3
Disclosed:
Jan 24, 2025

CVE-2025-24714 on NVD →

Bubble Menu – Floating Button Menu with Sticky Navigation [bubble-menu] < 3.0.5

unknown

[en] The Bubble Menu WordPress plugin before 3.0.5 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example, in multisite setup).

Affected:
up to 3.0.5
Fixed in:
3.0.5
Disclosed:
Aug 7, 2023

CVE-2023-3650 on NVD →

Bubble Menu <= 3.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Bubble Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary...

CVSS:
4.4
Affected:
up to 3.0.5
Fixed in:
3.0.5
Disclosed:
Jul 17, 2023

CVE-2023-3650 on NVD →

Bubble Menu – Floating Button Menu with Sticky Navigation [bubble-menu] < 3.0.4

unknown

[en] The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5...

Affected:
up to 3.0.4
Fixed in:
3.0.4
Disclosed:
Jun 12, 2023

CVE-2023-2362 on NVD →

Multiple Wow-Company Plugins (Various Versions) -- Reflected Cross-Site Scripting via 'page' parameter

medium

Several plugins by Wow-Company are vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in various versions due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully tri...

CVSS:
6.1
Affected:
up to 3.0.3
Fixed in:
3.0.4
Disclosed:
May 22, 2023

CVE-2023-2362 on NVD →

Bubble Menu – Floating Button Menu with Sticky Navigation [bubble-menu] < 3.0.2

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Bubble Menu – circle floating menu plugin <= 3.0.1 leading to form deletion.

Affected:
up to 3.0.2
Fixed in:
3.0.2
Disclosed:
Mar 1, 2023

CVE-2023-23984 on NVD →

Bubble Menu – circle floating menu <= 3.0.1 - Cross Site Request Forgery

medium

The Bubble Menu – circle floating menu plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 3.0.1. This is due to missing nonce validation in the ~/admin/page-main.php file. This makes it possible for unauthenticated attackers to delete menu items via a forged request grant...

CVSS:
4.3
Affected:
up to 3.0.1
Fixed in:
3.0.2
Disclosed:
Jan 20, 2023

CVE-2023-23984 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database