Input validation vulnerability in Sticky Buttons – floating buttons builder 3.1.0

The Sticky Buttons plugin for WordPress has a security vulnerability that could allow an unauthenticated user (someone who is not logged in) to inject malicious web scripts into web pages. This vulnerability affects versions up to, and including, 3.1.0 because the plugin does not properly sanitize input and escape output. To exploit this vulnerability, an attacker could create a link or button that once clicked could lead to malicious web scripts being executed on the user’s device.

Detected in:

Sticky Buttons – floating buttons builder fixed vulnerable versions: >= 0 <= 0

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.