CVE-2025-26881: WordPress Sticky Content plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Sticky Content sticky-menu-block allows Stored XSS.This issue affects Sticky Content: from n/a through <= 1.0.1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26881?
The severity of CVE-2025-26881 is classified as high due to the potential for stored Cross-Site Scripting (XSS) attacks.
How do I fix CVE-2025-26881?
To fix CVE-2025-26881, update bPlugins Sticky Content to version 1.0.2 or later.
Can CVE-2025-26881 affect user data?
Yes, CVE-2025-26881 can compromise user data by allowing attackers to execute scripts in the context of the affected site.
Is CVE-2025-26881 related to WordPress?
Yes, CVE-2025-26881 affects both bPlugins Sticky Content and WordPress Sticky Content versions up to 1.0.1.
What are the symptoms of CVE-2025-26881 exploitation?
Exploitation of CVE-2025-26881 may result in unauthorized actions being performed on behalf of users or data manipulation.