plugin

Floating Button Vulnerabilities

3 known security issues reported for the Floating Button WordPress plugin. Most recent disclosed Jan 5, 2024.

1 medium

Running Floating Button on your site? Check whether your installed version is affected.

Scan your site free

Floating Button [floating-button] < 6.0.1

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Jan 5, 2024

CVE-2023-52149 on NVD →

Floating Button <= 6.0 - Cross-Site Request Forgery via process_bulk_action

medium

The Floating Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to process bulk actions via a forged request granted...

CVSS:
4.3
Affected:
up to 6.0
Fixed in:
6.0.1
Disclosed:
Dec 28, 2023

CVE-2023-52149 on NVD →

Floating Button [floating-button] < 5.3.1

unknown

[en] The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5...

Affected:
up to 5.3.1
Fixed in:
5.3.1
Disclosed:
Jun 12, 2023

CVE-2023-2362 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database