CVE · Medium

CVE-2021-24425 — My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.5.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24425 My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.5.2 2.5.2 2021-06-21

CVE-2021-24425

The myStickymenu plugin before version 2.5.2 fails to properly sanitize the Bar Text settings, permitting high-privilege users to inject malicious JavaScript code. This stored cross-site scripting vulnerability executes whenever the Welcome bar is active, affecting both the plugin's settings page and all front-end pages of the website.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.