First published: Mon Feb 07 2022(Updated: )
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Premio All-in-one Floating Contact Form – My Sticky Elements | <2.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Vulnerability CVE-2022-0148 refers to a reflected XSS vulnerability in the All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before version 2.0.4.
The severity of vulnerability CVE-2022-0148 is medium with a CVSS score of 5.4.
Vulnerability CVE-2022-0148 affects All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin versions up to, but excluding, 2.0.4.
To fix vulnerability CVE-2022-0148, you should update the All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin to version 2.0.4 or later.
The Common Weakness Enumeration (CWE) ID for vulnerability CVE-2022-0148 is CWE-79, which refers to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').