The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
History

Wed, 11 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Premio
Premio my Sticky Bar
Weaknesses CWE-79
CPEs cpe:2.3:a:premio:my_sticky_bar:*:*:*:*:*:wordpress:*:*
Vendors & Products Premio
Premio my Sticky Bar

Tue, 20 May 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 15 May 2025 20:15:00 +0000

Type Values Removed Values Added
Description The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Title My Sticky Bar < 2.6.8 - Admin+ Stored XSS
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-05-15T20:09:44.129Z

Updated: 2025-05-20T14:22:29.007Z

Reserved: 2024-03-19T13:36:31.527Z

Link: CVE-2024-2643

cve-icon Vulnrichment

Updated: 2025-05-20T14:22:17.609Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-15T20:15:49.837

Modified: 2025-06-11T14:45:57.147

Link: CVE-2024-2643

cve-icon Redhat

No data.