plugin

Mystickyelements Vulnerabilities

12 known security issues reported for the Mystickyelements WordPress plugin. Most recent disclosed Jan 1, 2026.

1 high 5 medium

Running Mystickyelements on your site? Check whether your installed version is affected.

Scan your site free

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs &#8211; My Sticky Elements [mystickyelements] < 2.3.4

unknown

[en] The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possib...

Affected:
up to 2.3.4
Fixed in:
2.3.4
Disclosed:
Jan 1, 2026

CVE-2025-14428 on NVD →

My Sticky Elements <= 2.3.3 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk Lead Deletion

medium

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possible fo...

CVSS:
4.3
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Dec 31, 2025

CVE-2025-14428 on NVD →

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs &#8211; My Sticky Elements [mystickyelements] <= 2.3.3 (unfixed + closed)

unknown

[en] Missing Authorization vulnerability in Gal Dubinski My Sticky Elements mystickyelements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects My Sticky Elements: from n/a through <= 2.3.3.

Affected:
up to 2.3.3
Fix:
No patched version reported
Disclosed:
Dec 30, 2025

CVE-2025-68995 on NVD →

My Sticky Elements <= 2.3.3 - Missing Authorization

medium

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 2.3.3. This makes it possible for authenticated attackers, with...

CVSS:
4.3
Affected:
up to 2.3.3
Fixed in:
2.3.4
Disclosed:
Dec 25, 2025

CVE-2025-68995 on NVD →

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs &#8211; My Sticky Elements [mystickyelements] < 2.1.4 (closed)

unknown

[en] Missing Authorization vulnerability in Premio All-in-one Floating Contact Form – My Sticky Elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All-in-one Floating Contact Form – My Sticky Elements: from n/a through 2.1.3.

Affected:
up to 2.1.4
Fixed in:
2.1.4
Disclosed:
Dec 9, 2024

CVE-2023-51362 on NVD →

All-in-one Floating Contact Form – My Sticky Elements <= 2.1.3 - Missing Authorization

medium

The All-in-one Floating Contact Form – My Sticky Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.1.3. This makes it possible for unauthenticated attackers to perform an unauthorized action.

CVSS:
5.3
Affected:
up to 2.1.3
Fixed in:
2.1.4
Disclosed:
Dec 26, 2023

CVE-2023-51362 on NVD →

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs &#8211; My Sticky Elements [mystickyelements] < 2.1.2 (closed)

unknown

[en] The All-in-one Floating Contact Form WordPress plugin before 2.1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Jul 24, 2023

CVE-2023-3248 on NVD →

All-in-one Floating Contact Form <= 2.1.1 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings

medium

The All-in-one Floating Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above...

CVSS:
4.4
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Jul 3, 2023

CVE-2023-3248 on NVD →

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs &#8211; My Sticky Elements [mystickyelements] < 2.0.9 (closed)

unknown

[en] The My Sticky Elements WordPress plugin before 2.0.9 does not properly sanitise and escape a parameter before using it in a SQL statement when deleting messages, leading to a SQL injection exploitable by high privilege users such as admin

Affected:
up to 2.0.9
Fixed in:
2.0.9
Disclosed:
Feb 27, 2023

CVE-2023-0487 on NVD →

My Sticky Elements <= 2.0.8 - Authenticated (Admin+) SQL Injection

high

The My Sticky Elements plugin for WordPress is vulnerable to SQL Injection via the 'delete_message' parameter in versions up to, and including, 2.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attack...

CVSS:
7.2
Affected:
2.0.8 – 2.0.8
Fixed in:
2.0.9
Disclosed:
Feb 9, 2023

CVE-2023-0487 on NVD →

All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs &#8211; My Sticky Elements [mystickyelements] < 2.0.4 (closed)

unknown

[en] The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

Affected:
up to 2.0.4
Fixed in:
2.0.4
Disclosed:
Feb 7, 2022

CVE-2022-0148 on NVD →

All-in-one Floating Contact Form <= 2.0.3 - Reflected Cross-Site Scripting

medium

The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

CVSS:
6.1
Affected:
up to 2.0.3
Fixed in:
2.0.4
Disclosed:
Jan 10, 2022

CVE-2022-0148 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database