PLUGIN SECURITY

Is Mystickymenu safe?

Create a welcome notification bar for your website. Also, My Sticky Bar plugin can make your menu or header sticky to the top when scrolled 📌

What this plugin does

  • Slug: mystickymenu
  • Author: Premio
  • 100000+ active installs
  • 98/100 rating (1196 reviews on wordpress.org)
  • 4159211 all-time downloads
  • On WordPress.org since 2014-03-06

floating barnotification barsticky barsticky headersticky menu

Maintenance status

  • Latest known version: 2.9.1
  • Last updated: 2026-08-13 7:36am GMT
  • Tested up to WordPress: 7.1
  • Max supported PHP (analyzed): 8.4

Known vulnerabilities

7 known CVEs on file for Mystickymenu.

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-7133 My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.7.3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.7.3 2.7.3 2024-08-23 ✓ fixed in latest
CVE-2024-4090 My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.7.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.7.2 2.7.2 2024-07-11 ✓ fixed in latest
CVE-2023-7048 My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.6.7 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.6.7 2.6.7 2024-01-03 ✓ fixed in latest
CVE-2023-5509 My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.6.5 Missing Authorization Medium 5.4 < 2.6.5 2.6.5 2023-10-27 ✓ fixed in latest
CVE-2021-24425 My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.5.2 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.5.2 2.5.2 2021-06-21 ✓ fixed in latest
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.6.8 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 2.6.8 2.6.8 0000-00-00 ✓ fixed in latest
My Sticky Bar – Floating Notification Bar & Sticky Header (formerly myStickymenu) [mystickymenu] < 2.8.7 Unknown < 2.8.7 2.8.7 0000-00-00 ✓ fixed in latest
CVE-2024-2643 My Sticky Bar < 2.6.8 - Admin+ Stored XSS Unknown < 2.6.8 2.6.8 ✓ fixed in latest
+ 1 more known vulnerability
CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-3657 My Sticky Bar < 2.8.7 - Unauthenticated SQLi via 'stickymenu_contact_lead_form' Action Unknown < 2.8.7 2.8.7 ✓ fixed in latest

How to fix it

Keep Mystickymenu updated — 2.9.1 is the latest version on wordpress.org, and each CVE above lists the exact release that fixed it ("Fixed in").

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.