CVE Database
/

CVE-2022-2375

Back to search

CVE-2022-2375

Published: Aug 22, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

VendorProductVersions

Unknown

WP Sticky Button – Click to Chat

affected
1.4.1 - < 1.4.1

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now