« Volver al listado

CVE-2022-2375

Estado: ModificadaMedia (5.4)—

The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-2375",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.3
      }
    ]
  },
  "affected": [
    {
      "source": "contact@wpscan.com",
      "affectedData": [
        {
          "vendor": "Unknown",
          "product": "WP Sticky Button – Click to Chat",
          "versions": [
            {
              "status": "affected",
              "version": "1.4.1",
              "lessThan": "1.4.1",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-08-22T15:15:14.677",
  "references": [
    {
      "url": "https://wpscan.com/vulnerability/caab1fca-cc6b-45bb-bd0d-f857edd8bb81",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "contact@wpscan.com"
    },
    {
      "url": "https://wpscan.com/vulnerability/caab1fca-cc6b-45bb-bd0d-f857edd8bb81",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "contact@wpscan.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        },
        {
          "lang": "en",
          "value": "CWE-352"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The WP Sticky Button WordPress plugin before 1.4.1 does not have authorisation and CSRF checks when saving its settings, allowing unauthenticated users to update them. Furthermore, due to the lack of escaping in some of them, it could lead to Stored Cross-Site Scripting issues"
    },
    {
      "lang": "es",
      "value": "El plugin WP Sticky Button de WordPress versiones anteriores a 1.4.1, no dispone de comprobaciones de autorización y de tipo CSRF cuando guarda sus configuraciones, lo que permite a usuarios no autenticados actualizarlas. Además, debido a una falta de escapes en algunos de ellos, podría conllevar a problemas de tipo Cross-Site Scripting Almacenado"
    }
  ],
  "lastModified": "2026-06-17T04:41:47.000",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:okapitech:wp_sticky_button:*:*:*:*:*:wordpress:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D6674C2-654C-4AA0-AF70-314B9624FDE5",
              "versionEndExcluding": "1.4.1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "contact@wpscan.com"
}