WordPress · Floating Contact Button · CVE-2024-7891
**Name of the Vulnerable Software and Affected Versions**
The Floating Contact Button WordPress plugin versions prior to 2.8
**Description**
The issue is related to the lack of sanitization and escaping of some settings in the plugin, which could allow high-privilege users, such as admins, to perform Cross-Site Scripting attacks, even when unfiltered html is disallowed. This could potentially lead to site compromise.
**Recommendations**
For versions prior to 2.8, upgrade the plugin to version 2.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's settings to minimize the risk of exploitation.