Floating Button [floating-button] < 6.0.1
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Floating Button.This issue affects Floating Button: from n/a through 6.0.
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
- Disclosed:
- Jan 5, 2024
CVE-2023-52149 on NVD →
Floating Button <= 6.0 - Cross-Site Request Forgery via process_bulk_action
medium
The Floating Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 6.0. This is due to missing or incorrect nonce validation on the process_bulk_action function. This makes it possible for unauthenticated attackers to process bulk actions via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 6.0
- Fixed in:
- 6.0.1
- Disclosed:
- Dec 28, 2023
CVE-2023-52149 on NVD →
Floating Button [floating-button] < 5.3.1
unknown
[en] The Float menu WordPress plugin before 5.0.2, Bubble Menu WordPress plugin before 3.0.4, Button Generator WordPress plugin before 2.3.5, Calculator Builder WordPress plugin before 1.5.1, Counter Box WordPress plugin before 1.2.2, Floating Button WordPress plugin before 5.3.1, Herd Effects WordPress plugin before 5...
- Affected:
- up to 5.3.1
- Fixed in:
- 5.3.1
- Disclosed:
- Jun 12, 2023
CVE-2023-2362 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database