VDB

CISA-2023-3666

CISA-2023-3666 PUBLISHED CVSS 3.3 LOW

Reported by WPScan · Published September 3, 2025

The Sticky Side Buttons WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

Risk Scores

CVSS 3.1
3.3
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:N

Affected Products

VendorProductVersions
UnknownSticky Side Buttons0
UnknownSticky Side Buttons0, 0

Timeline

  • Sep 3, 2025 CVE Published
  • Sep 3, 2025 CVE Updated

References

  • exploitvdb-entrytechnical-description
Open in Interactive Console →
$ Console Community · 100/wk Open console ›