Record summary

CVE-2022-0148 has a selected CVSS score of 5.4 (medium); EIP currently links 1 Nuclei template.

Description

The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs – My Sticky Elements

CVE List2.0.4 to < 2.0.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress All-in-one Floating Contact Form <2.0.4 - Cross-Site ScriptingCVSS 5.4

WordPress All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs plugin before 2.0.4 contains a reflected cross-site scripting vulnerability on the my-sticky-elements-leads admin page.

Impact

Successful exploitation of this vulnerability could allow an attacker to inject malicious scripts into the affected website, leading to potential data theft, session hijacking, or defacement.

Remediation

Update the WordPress All-in-one Floating Contact Form plugin to version 2.0.4 or later to mitigate the vulnerability.

WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscvecve2022xsswp-pluginauthenticatedwpscanwordpresspremiovuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:premio:mystickyelements:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

3