plugin

Mystickymenu Vulnerabilities

13 known security issues reported for the Mystickymenu WordPress plugin. Most recent disclosed Mar 12, 2026.

1 critical 1 high 4 medium 1 low

Running Mystickymenu on your site? Check whether your installed version is affected.

Scan your site free

My Sticky Bar - Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action vulnerability

critical

Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action vulnerability

CVSS:
9.3
Affected:
up to 2.8.6
Fixed in:
2.8.7
Disclosed:
Mar 12, 2026

My Sticky Bar <= 2.8.6 - Unauthenticated SQL Injection via 'stickymenu_contact_lead_form' Action

high

The My Sticky Bar plugin for WordPress is vulnerable to SQL injection via the `stickymenu_contact_lead_form` AJAX action in all versions up to, and including, 2.8.6. This is due to the handler using attacker-controlled POST parameter names directly as SQL column identifiers in `$wpdb->insert()`. While parameter values...

CVSS:
7.5
Affected:
up to 2.8.6
Fixed in:
2.8.7
Disclosed:
Mar 11, 2026

CVE-2026-3657 on NVD →

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme &#8211; My Sticky Bar (formerly myStickymenu) [mystickymenu] < 2.7.3

unknown

[en] The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks.

Affected:
up to 2.7.3
Fixed in:
2.7.3
Disclosed:
Sep 13, 2024

CVE-2024-7133 on NVD →

My Sticky Bar <= 2.7.2 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.2 due to insufficient input sanitization and o...

CVSS:
4.4
Affected:
up to 2.7.2
Fixed in:
2.7.3
Disclosed:
Aug 23, 2024

CVE-2024-7133 on NVD →

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme &#8211; My Sticky Bar (formerly myStickymenu) [mystickymenu] < 2.7.2

unknown

[en] The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowe...

Affected:
up to 2.7.2
Fixed in:
2.7.2
Disclosed:
Aug 1, 2024

CVE-2024-4090 on NVD →

My Sticky Bar (formerly myStickymenu) <= 2.7.1 - Authenticated (Admin+) Stored Cross-Site Scripting

medium

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.1 due to insufficient input sanitization and o...

CVSS:
4.4
Affected:
up to 2.7.1
Fixed in:
2.7.2
Disclosed:
Jul 11, 2024

CVE-2024-4090 on NVD →

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme &#8211; My Sticky Bar (formerly myStickymenu) [mystickymenu] < 2.6.7

unknown

[en] The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.6. This is due to missing or incorrect nonce validation in mystickymenu-contact-leads.php. This makes it possible for unauthenticated attackers to trigger the export of a CSV file containing...

Affected:
up to 2.6.7
Fixed in:
2.6.7
Disclosed:
Jan 11, 2024

CVE-2023-7048 on NVD →

My Sticky Bar <= 2.6.6 - Cross-Site Request Forgery to Sensitive Information Exposure

low

The My Sticky Bar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.6.6. This is due to missing or incorrect nonce validation in mystickymenu-contact-leads.php. This makes it possible for unauthenticated attackers to trigger the export of a CSV file containing cont...

CVSS:
3.1
Affected:
up to 2.6.6
Fixed in:
2.6.7
Disclosed:
Jan 3, 2024

CVE-2023-7048 on NVD →

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme &#8211; My Sticky Bar (formerly myStickymenu) [mystickymenu] < 2.6.5

unknown

[en] The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.

Affected:
up to 2.6.5
Fixed in:
2.6.5
Disclosed:
Nov 20, 2023

CVE-2023-5509 on NVD →

myStickymenu <= 2.6.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Form Lead Deletion

medium

The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the my_sticky_menu_bulks() function in all versions up to, and i...

CVSS:
6.3
Affected:
up to 2.6.4
Fixed in:
2.6.5
Disclosed:
Oct 27, 2023

CVE-2023-5509 on NVD →

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme &#8211; My Sticky Bar (formerly myStickymenu) [mystickymenu] < 2.5.2

unknown

[en] The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be trigg...

Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Aug 2, 2021

CVE-2021-24425 on NVD →

myStickymenu <= 2.5.1 - Authenticated Stored Cross-Site Scripting

medium

The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered...

CVSS:
4.8
Affected:
up to 2.5.2
Fixed in:
2.5.2
Disclosed:
Jun 21, 2021

CVE-2021-24425 on NVD →

Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme &#8211; My Sticky Bar (formerly myStickymenu) [mystickymenu] < 2.6.8

unknown
Affected:
up to 2.6.8
Fixed in:
2.6.8

CVE-2024-2643 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database