CVE-2023-51362 – WordPress myStickyElements plugin <= 2.1.3 - Broken Access Control vulnerability
https://notcve.org/view.php?id=CVE-2023-51362
26 Dec 2023 — Missing Authorization vulnerability in Premio All-in-one Floating Contact Form – My Sticky Elements allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects All-in-one Floating Contact Form – My Sticky Elements: from n/a through 2.1.3. The All-in-one Floating Contact Form – My Sticky Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.1.3. This makes it possible for u... • https://patchstack.com/database/wordpress/plugin/mystickyelements/vulnerability/wordpress-mystickyelements-plugin-2-1-3-broken-access-control-vulnerability?_s_id=cve • CWE-862: Missing Authorization •
CVE-2022-0148 – All-in-one Floating Contact Form < 2.0.4 - Authenticated Reflected Cross-Site Scripting (XSS)
https://notcve.org/view.php?id=CVE-2022-0148
10 Jan 2022 — The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page. El plugin All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs de WordPress versiones anteriores a 2.0.4, era vulnerable a un ataque de tipo XSS reflejado en la página de administración my-sticky-elements-leads • https://plugins.trac.wordpress.org/changeset/2654453/mystickyelements • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •