First published: Fri Jan 24 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons allows Cross Site Request Forgery. This issue affects Sticky Buttons: from n/a through 4.1.1.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress Sticky Buttons Plugin | <=4.1.1 | |
WordPress Sticky Button | <=4.1.1 |
Update the WordPress Sticky Buttons wordpress plugin to the latest available version (at least 4.1.2).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-24720 is classified as a moderate risk due to its potential for Cross-Site Request Forgery.
To fix CVE-2025-24720, update the Wow-Company Sticky Buttons plugin to version 4.1.2 or later.
CVE-2025-24720 affects all versions of Sticky Buttons from n/a to 4.1.1.
CVE-2025-24720 is a Cross-Site Request Forgery (CSRF) vulnerability.
Yes, CVE-2025-24720 can be exploited remotely by an attacker to perform unauthorized actions.