Floating Action Button <= 1.2.1 - Cross-Site Request Forgery
medium
The Floating Action Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wp_ajax_fz_fab_settings_save function. This makes it possible for unauthenticated attackers to change plugin settings via a...
- CVSS:
- 4.3
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- Nov 20, 2023
Floating Action Button [floating-action-button] < 1.2.2
unknown
The Floating Action Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wp_ajax_fz_fab_settings_save function. This makes it possible for unauthenticated attackers to change plugin settings via a...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Nov 20, 2023
Floating Action Button [floating-action-button] < 1.2.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Faraz Quazi Floating Action Button plugin <= 1.2.1 versions.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Nov 9, 2023
CVE-2023-31088 on NVD →
Floating Action Button <= <=1.2.1 - Cross-Site Request Forgery to Settings Modification
medium
The Floating Action Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, <=1.2.1. This is due to missing or incorrect nonce validation on the 'wp_ajax_fz_fab_settings_save' AJAX action. This makes it possible for unauthenticated attackers to modify plugin settings vi...
- CVSS:
- 4.3
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- May 31, 2023
CVE-2023-31088 on NVD →
Floating Action Button <= 1.2 - Missing Authorization
high
The Floating Action Button plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.2 due to a missing capability check and nonce validation on the fz_fab_settings_save() function that is called via an AJAX action (including a nopriv action). This makes it possible for unauthentica...
- CVSS:
- 7.3
- Affected:
- up to 1.2
- Fixed in:
- 1.2.1
- Disclosed:
- Aug 9, 2022
Floating Action Button [floating-action-button] < 1.2.1
unknown
The Floating Action Button plugin for WordPress is vulnerable to authorization bypass in versions up to, and including, 1.2 due to a missing capability check and nonce validation on the fz_fab_settings_save() function that is called via an AJAX action (including a nopriv action). This makes it possible for unauthentica...
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.1
- Disclosed:
- Aug 9, 2022
Floating Action Button [floating-action-button] < 1.2.2
unknown
The plugin does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database