Floating Social Bar <= 1.1.7 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Floating Social Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.1.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in...
- CVSS:
- 4.4
- Affected:
- up to 1.1.7
- Fix:
- No patched version reported
- Disclosed:
- Apr 24, 2025
CVE-2025-46451 on NVD →
Floating Social Bar <= 1.1.6 - Unauthenticated Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the Floating Social Bar plugin before 1.1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via vectors related to original service order.
- CVSS:
- 6.1
- Affected:
- up to 1.1.6
- Fixed in:
- 1.1.7
- Disclosed:
- Jul 7, 2015
CVE-2015-3299 on NVD →
Floating Social Bar < 1.1.7 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php.
- CVSS:
- 6.1
- Affected:
- up to 1.1.7
- Fixed in:
- 1.1.7
- Disclosed:
- Jul 7, 2015
CVE-2015-5528 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database