CVE-2026-28170: WordPress Blog Floating Button plugin <= 1.4.20 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in Blog Floating Button <= 1.4.20 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Blog Floating Button pluginto a version that resolves this vulnerability.Fixed in 1.4.21
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28170?
CVE-2026-28170 has a severity rating of high with a score of 7.1.
What is CVE-2026-28170 vulnerability?
CVE-2026-28170 is a Cross Site Scripting (XSS) vulnerability found in the WordPress Blog Floating Button plugin versions 1.4.20 and below.
How do I fix CVE-2026-28170?
To fix CVE-2026-28170, update the Blog Floating Button plugin to the latest version that addresses the XSS vulnerability.
Who is affected by CVE-2026-28170?
Anyone using the Blog Floating Button plugin for WordPress versions 1.4.20 and earlier is affected by CVE-2026-28170.
What type of attack does CVE-2026-28170 enable?
CVE-2026-28170 enables unauthenticated Cross Site Scripting (XSS) attacks, potentially allowing attackers to execute malicious scripts.