Vulnerabilities
Vulnerable Software
Premio:  >> Mystickymenu  Security Vulnerabilities
The myStickymenu WordPress plugin before 2.6.5 does not adequately authorize some ajax calls, allowing any logged-in user to perform the actions.
CVSS Score
5.4
EPSS Score
0.001
Published
2023-11-20
The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)
CVSS Score
4.8
EPSS Score
0.002
Published
2021-08-02


Contact Us

Shodan ® - All rights reserved