Impact
The Sticky Action Buttons plugin for WordPress suffers from a Cross‑Site Request Forgery flaw caused by missing or incorrect nonce validation in the sabs_options_page_form_submit() function. This weakness (CWE‑352) allows an unauthenticated attacker to forge a request that updates plugin settings when an administrator unknowingly clicks a malicious link. The result is an unauthorized change to the plugin’s configuration, which could lead to misconfiguration, service disruption, or provide a foothold for subsequent exploitation.
Affected Systems
All installations of the Sticky Action Buttons plugin by praveentamil in WordPress, including every release up to and including version 1.1, are affected. Versions newer than 1.1 have the fix applied and are not vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity level, while the EPSS score of less than 1% suggests that active exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is a CSRF scenario that relies on deceiving an administrator into submitting a forged request, so the overall risk remains moderate but the probability of exploitation is very low due to the requirement of social engineering and site‑admin interaction.
OpenCVE Enrichment