Cross-site Scripting Flaw in Floating Social Bar by Syed Balkhi
CVE-2025-46451

5.9MEDIUM

Key Information:

Vendor
CVE Published:
24 April 2025

What is CVE-2025-46451?

A Cross-site Scripting (XSS) vulnerability exists in the Floating Social Bar plugin developed by Syed Balkhi. This flaw allows for stored XSS attacks, where malicious scripts can be injected and executed within a user's browser session. This poses a significant risk as it enables an attacker to steal sensitive information, manipulate user sessions, and perform unauthorized actions within the context of the affected site. The vulnerability affects all versions from n/a up to and including version 1.1.7.

Affected Version(s)

Floating Social Bar 0 <= 1.1.7

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nabil Irawan (Patchstack Alliance)
.