The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-08-01T06:00:05.396Z

Updated: 2024-08-01T13:36:51.336Z

Reserved: 2024-04-23T18:20:01.515Z

Link: CVE-2024-4090

cve-icon Vulnrichment

Updated: 2024-08-01T13:36:44.206Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-01T06:15:02.587

Modified: 2024-08-01T14:35:12.593

Link: CVE-2024-4090

cve-icon Redhat

No data.