WordPress Plugin Vulnerabilities
Sticky Menu, Sticky Header (or anything!) on Scroll < 2.21 - CSRF & XSS
Description
Antony Garand of Sucuri discovered that multiple WordPress plugins were vulnerable to Cross-Site Scripting (XSS) within the admin panel, which could be exploited by using s Cross-Site Request Forgery (CSRF) attack.
Affects Plugins
References
Classification
Type
XSS
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Antony Garand (Sucuri)
Verified
No
WPVDB ID
Timeline
Publicly Published
2020-09-09 (about 5 years ago)
Added
2020-09-09 (about 5 years ago)
Last Updated
2020-09-10 (about 5 years ago)