CVE · Medium

CVE-2023-7048 — My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.6.7

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-7048 My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.6.7 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.6.7 2.6.7 2024-01-03

CVE-2023-7048

The My Sticky Bar plugin for WordPress contains a cross-site request forgery vulnerability in versions up to 2.6.6 due to inadequate nonce verification in the mystickymenu-contact-leads.php file. An unauthenticated attacker can exploit this flaw by crafting a malicious request that, when clicked by an administrator, triggers the export of contact leads data to a CSV file. The exported file is temporarily stored in a public directory, creating a narrow window of opportunity for the attacker to download the sensitive information before the system automatically removes it.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.