CVE Feed

    Dashboard / CVE / CVE-2021-24425

    CVE-2021-24425

    The Floating Notification Bar, Sticky Menu on Scroll, and Sticky Header for Any Theme – myStickymenu WordPress plugin before 2.5.2 does not sanitise or escape its Bar Text settings, allowing hight privilege users to use malicious JavaScript in it, leading to a Stored Cross-Site Scripting issue, which will be triggered in the plugin's setting, as well as all front-page of the blog (when the Welcome bar is active)

    Published:Aug 2, 2021
    Last Modified:Nov 21, 2024
    EPS:Aug 2, 2021
    EPSS Score:0.00206
    CVSS Score:4.8

    Affected Products

    Vendor
    Premio
    Product
    Mystickymenu

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High