WordPress · Floating Social Bar · CVE-2015-3299
**Name of the Vulnerable Software and Affected Versions**
Floating Social Bar plugin versions prior to 1.1.7
**Description**
The issue is related to a cross-site scripting (XSS) vulnerability, which allows remote attackers to inject arbitrary web script or HTML. This is achieved through vectors related to the original service order.
**Recommendations**
For versions prior to 1.1.7, update to version 1.1.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the Floating Social Bar plugin until the update is applied.