CVE-2025-24720: WordPress Sticky Buttons Plugin <= 4.1.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Published Jan 24, 2025
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Wow-Company Sticky Buttons sticky-buttons allows Cross Site Request Forgery.This issue affects Sticky Buttons: from n/a through <= 4.1.1.
Affected Software
1 affected component
Wow-Company Sticky Buttons<=4.1.1
Remediation
Information
Update the WordPress Sticky Buttons wordpress plugin to the latest available version (at least 4.1.2).
Event History
Jan 24, 2025
CVE Published
via MITRE·05:25 PM
Data Sourced
via MITRE·05:25 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24720?
The severity of CVE-2025-24720 is classified as a moderate risk due to its potential for Cross-Site Request Forgery.
2
How do I fix CVE-2025-24720?
To fix CVE-2025-24720, update the Wow-Company Sticky Buttons plugin to version 4.1.2 or later.
3
What versions of Sticky Buttons are affected by CVE-2025-24720?
CVE-2025-24720 affects all versions of Sticky Buttons from n/a to 4.1.1.
4
What type of vulnerability is CVE-2025-24720?
CVE-2025-24720 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Can CVE-2025-24720 be exploited remotely?
Yes, CVE-2025-24720 can be exploited remotely by an attacker to perform unauthorized actions.