CVE-2024-4149: Floating Chat Widget < 3.2.3 - Admin+ Stored XSS
The Floating Chat Widget: Contact Chat Icons, WhatsApp, Telegram Chat, Line Messenger, WeChat, Email, SMS, Call Button WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfilteredhtml capability is disallowed (for example in multisite setup).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4149?
CVE-2024-4149 is considered a high severity vulnerability due to its potential for Stored Cross-Site Scripting attacks.
How do I fix CVE-2024-4149?
To fix CVE-2024-4149, update the Premio Floating Chat Widget plugin to version 3.2.3 or later.
Who is affected by CVE-2024-4149?
CVE-2024-4149 affects users of the Premio Floating Chat Widget WordPress plugin prior to version 3.2.3.
What type of vulnerability is CVE-2024-4149?
CVE-2024-4149 is a Stored Cross-Site Scripting vulnerability that affects certain settings in the plugin.
Can administrators be targeted by CVE-2024-4149?
Yes, high privilege users, including administrators, can be targeted by CVE-2024-4149 due to the lack of proper sanitization and escaping of plugin settings.