The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
Link | Tags |
---|---|
https://wpscan.com/vulnerability/37665ee1-c57f-4445-9596-df4f7d72c8cd | third party advisory exploit |
https://plugins.trac.wordpress.org/changeset/2654453/mystickyelements | third party advisory patch |