CVE-2023-3225: Float menu < 5.0.3 - Admin+ Stored Cross-Site Scripting
The Float menu WordPress plugin before 5.0.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for the Float menu WordPress plugin?
The vulnerability ID for the Float menu WordPress plugin is CVE-2023-3225.
What is the impact of CVE-2023-3225?
CVE-2023-3225 allows high privilege users to perform Stored Cross-Site Scripting attacks.
How can high privilege users exploit CVE-2023-3225?
High privilege users, such as admin, can exploit CVE-2023-3225 by not sanitizing and escaping some of the plugin's settings.
Is the vulnerability CVE-2023-3225 applicable to all versions of the Float menu plugin?
No, the vulnerability CVE-2023-3225 is applicable to versions up to and excluding 5.0.3 of the Float menu plugin.
What is the severity level of CVE-2023-3225?
The severity level of CVE-2023-3225 is medium with a value of 4.
How can I fix CVE-2023-3225?
To fix CVE-2023-3225, update the Float menu WordPress plugin to version 5.0.3 or above.