PT-2021-21379 · WordPress · Wordpress Floating Social Media Icon

Asif Nawaz

+1

·

Published

2021-11-26

·

Updated

2021-11-26

·

CVE-2021-36843

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WordPress Floating Social Media Icon plugin versions <= 4.3.5
Description An Authenticated Stored Cross-Site Scripting (XSS) issue was found in the Social Media Configuration form of the WordPress Floating Social Media Icon plugin. This issue requires a high-role user, such as an admin, to exploit.
Recommendations For WordPress Floating Social Media Icon plugin versions <= 4.3.5, update to a version higher than 4.3.5 to resolve the issue. As a temporary workaround, consider restricting access to the Social Media Configuration form to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-36843

Affected Products

Wordpress Floating Social Media Icon