All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] < 2.3.4
unknown
[en] The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possib...
- Affected:
- up to 2.3.4
- Fixed in:
- 2.3.4
- Disclosed:
- Jan 1, 2026
CVE-2025-14428 on NVD →
My Sticky Elements <= 2.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk Lead Deletion
medium
The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possible fo...
- CVSS:
- 4.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Dec 31, 2025
CVE-2025-14428 on NVD →
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] <= 2.3.3 (unfixed + closed)
unknown
[en] Missing Authorization vulnerability in Gal Dubinski My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.3.3.
- Affected:
- up to 2.3.3
- Fix:
- No patched version reported
- Disclosed:
- Dec 30, 2025
CVE-2025-68995 on NVD →
My Sticky Elements <= 2.3.3 - Missing Authorization
medium
The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.3. This makes it possible for authenticated attackers, with...
- CVSS:
- 4.3
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.4
- Disclosed:
- Dec 25, 2025
CVE-2025-68995 on NVD →
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] < 2.1.4 (closed)
unknown
[en] Missing Authorization vulnerability in Premio All-in-one Floating Contact Form – My Sticky Elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All-in-one Floating Contact Form – My Sticky Elements: from n/a through 2.1.3.
- Affected:
- up to 2.1.4
- Fixed in:
- 2.1.4
- Disclosed:
- Dec 9, 2024
CVE-2023-51362 on NVD →
All-in-one Floating Contact Form – My Sticky Elements <= 2.1.3 - Missing Authorization
medium
The All-in-one Floating Contact Form – My Sticky Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.1.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 2.1.3
- Fixed in:
- 2.1.4
- Disclosed:
- Dec 26, 2023
CVE-2023-51362 on NVD →
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] < 2.1.2 (closed)
unknown
[en] The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Jul 24, 2023
CVE-2023-3248 on NVD →
All-in-one Floating Contact Form <= 2.1.1 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings
medium
The All-in-one Floating Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...
- CVSS:
- 4.4
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Jul 3, 2023
CVE-2023-3248 on NVD →
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] < 2.0.9 (closed)
unknown
[en] The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin
- Affected:
- up to 2.0.9
- Fixed in:
- 2.0.9
- Disclosed:
- Feb 27, 2023
CVE-2023-0487 on NVD →
My Sticky Elements <= 2.0.8 - Authenticated (Admin+) SQL Injection
high
The My Sticky Elements plugin for WordPress is vulnerable to SQL Injection via the 'delete_message' parameter in versions up to, and including, 2.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...
- CVSS:
- 7.2
- Affected:
- 2.0.8 – 2.0.8
- Fixed in:
- 2.0.9
- Disclosed:
- Feb 9, 2023
CVE-2023-0487 on NVD →
All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements [mystickyelements] < 2.0.4 (closed)
unknown
[en] The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
- Affected:
- up to 2.0.4
- Fixed in:
- 2.0.4
- Disclosed:
- Feb 7, 2022
CVE-2022-0148 on NVD →
All-in-one Floating Contact Form <= 2.0.3 - Reflected Cross-Site Scripting
medium
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
- CVSS:
- 6.1
- Affected:
- up to 2.0.3
- Fixed in:
- 2.0.4
- Disclosed:
- Jan 10, 2022
CVE-2022-0148 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database