Impact
Unauthenticated Cross Site Scripting (XSS) exists in the Blog Floating Button plugin through version 1.4.20, allowing attackers to inject arbitrary JavaScript into pages served by the affected WordPress site. This flaw may be used to deface content, steal user credentials, or hijack sessions by executing malicious code in the victim’s browser context. The vulnerability is a classic input validation error (CWE‑79).
Affected Systems
The affected product is the Blog Floating Button plugin developed by 1meril, version 1.4.20 and all earlier releases. WordPress sites that have installed or upgraded to these versions are vulnerable, while installations of version 1.4.21 or later are not affected.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk of damage, and the EPSS score is not available but the lack of authentication requirements suggests easy exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves an attacker supplying a malicious payload through a plugin parameter that is not properly sanitized; based on the description, it is inferred that the injection is reflected in generated page content.
OpenCVE Enrichment