Cross-Site Scripting Flaw in Floating Social Bar Plugin for WordPress
CVE-2015-3299

6.1MEDIUM

Key Information:

Vendor
Wordpress
Vendor
CVE Published:
19 September 2017

Summary

The Floating Social Bar plugin for WordPress is vulnerable to a Cross-Site Scripting (XSS) issue that permits remote attackers to inject arbitrary web scripts or HTML into user interfaces. This vulnerability can be exploited through specific vectors related to the original service order, compromising site security and user data. Website administrators are advised to update to version 1.1.7 or later to mitigate these risks.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.