CVE-2023-7048
The My Sticky Bar plugin for WordPress contains a cross-site request forgery vulnerability in versions up to 2.6.6 due to inadequate nonce verification in the mystickymenu-contact-leads.php file. An unauthenticated attacker can exploit this flaw by crafting a malicious request that, when clicked by an administrator, triggers the export of contact leads data to a CSV file. The exported file is temporarily stored in a public directory, creating a narrow window of opportunity for the attacker to download the sensitive information before the system automatically removes it.
Based on public CVE data (MITRE/NVD).