Description
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
Published: 2026-08-13
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Unauthenticated Cross Site Scripting (XSS) exists in the Blog Floating Button plugin through version 1.4.20, allowing attackers to inject arbitrary JavaScript into pages served by the affected WordPress site. This flaw may be used to deface content, steal user credentials, or hijack sessions by executing malicious code in the victim’s browser context. The vulnerability is a classic input validation error (CWE‑79).

Affected Systems

The affected product is the Blog Floating Button plugin developed by 1meril, version 1.4.20 and all earlier releases. WordPress sites that have installed or upgraded to these versions are vulnerable, while installations of version 1.4.21 or later are not affected.

Risk and Exploitability

The CVSS score of 7.1 indicates a high risk of damage, and the EPSS score is not available but the lack of authentication requirements suggests easy exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves an attacker supplying a malicious payload through a plugin parameter that is not properly sanitized; based on the description, it is inferred that the injection is reflected in generated page content.

Generated by OpenCVE AI on August 13, 2026 at 16:32 UTC.

Remediation

Vendor Solution

Update the WordPress Blog Floating Button plugin to the latest available version (at least 1.4.21).


OpenCVE Recommended Actions

  • Update the WordPress Blog Floating Button plugin to version 1.4.21 or later.
  • If an update cannot be applied immediately, temporarily disable or remove the Blog Floating Button plugin to prevent script injection.
  • Keep the core WordPress installation and other plugins up to date to reduce the overall attack surface.

Generated by OpenCVE AI on August 13, 2026 at 16:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Meril
Meril blog Floating Button
Wordpress
Wordpress wordpress
Vendors & Products Meril
Meril blog Floating Button
Wordpress
Wordpress wordpress

Thu, 13 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
Title WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Meril Blog Floating Button
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-13T15:18:10.484Z

Reserved: 2026-02-25T12:14:34.738Z

Link: CVE-2026-28170

cve-icon Vulnrichment

Updated: 2026-08-13T15:18:04.886Z

cve-icon NVD

Status : Deferred

Published: 2026-08-13T14:16:59.143

Modified: 2026-08-14T19:09:20.713

Link: CVE-2026-28170

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T16:45:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')