CVE-2021-24992: Buttonizer - Smart Floating Action Button < 2.5.5 - Admin+ Stored Cross-Site Scripting
The Smart Floating / Sticky Buttons WordPress plugin before 2.5.5 does not sanitise and escape some parameter before outputting them in attributes and page, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-24992?
CVE-2021-24992 is classified as a high severity vulnerability due to its potential for Cross-Site Scripting attacks.
What versions of the Smart Floating / Sticky Buttons WordPress plugin are affected by CVE-2021-24992?
CVE-2021-24992 affects the Smart Floating / Sticky Buttons WordPress plugin versions before 2.5.5.
How do I fix CVE-2021-24992?
To fix CVE-2021-24992, upgrade the Smart Floating / Sticky Buttons WordPress plugin to version 2.5.5 or later.
What type of attack does CVE-2021-24992 allow?
CVE-2021-24992 allows high privileged users to perform Cross-Site Scripting (XSS) attacks.
Who is most at risk from CVE-2021-24992?
Users with high privileges on WordPress sites using the affected plugin versions are most at risk from CVE-2021-24992.