The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks.
History

Fri, 27 Sep 2024 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79

Fri, 13 Sep 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Premio
Premio my Sticky Bar
CPEs cpe:2.3:a:premio:my_sticky_bar:*:*:*:*:*:wordpress:*:*
Vendors & Products Premio
Premio my Sticky Bar
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 13 Sep 2024 06:15:00 +0000

Type Values Removed Values Added
Description The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.7.3 does not validate and escape some of its settings before outputting them back in the page, which could allow users with a high role to perform Stored Cross-Site Scripting attacks.
Title My Sticky Bar < 2.7.3 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2024-09-13T06:00:03.935Z

Updated: 2024-09-13T15:24:30.807Z

Reserved: 2024-07-26T15:44:08.014Z

Link: CVE-2024-7133

cve-icon Vulnrichment

Updated: 2024-09-13T15:16:11.705Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-13T06:15:15.580

Modified: 2024-09-27T21:27:50.053

Link: CVE-2024-7133

cve-icon Redhat

No data.