WP Sticky Button <= 1.4 - Missing Authorization to Arbitrary Settings Update
medium
The WP Sticky Button plugin for WordPress is vulnerable to unauthenticated plugin settings update in versions up to, and including, 1.4, due to missing authorization on the okapi_wasb_save_settings AJAX action. This allows unauthenticated attackers to update arbitrary plugin settings.
- CVSS:
- 6.3
- Affected:
- up to 1.4
- Fixed in:
- 1.4.1
- Disclosed:
- Aug 1, 2022
CVE-2022-2375 on NVD →
WP Sticky Button <= 1.3 - Unauthenticated Stored Cross-Site Scripting
high
The WP Sticky Button plugin for WordPress is vulnerable to stored cross-site scripting in versions up to, and including, 1.3, due to insufficient sanitization and escaping on several parameters. This allows unauthenticated attackers to add a stored Cross-Site Scripting payload to the settings.
- CVSS:
- 7.2
- Affected:
- up to 1.3
- Fixed in:
- 1.4.0
- Disclosed:
- Jul 26, 2022
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database