Extension WordPress
Vulnérabilités All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
Cette page rassemble les failles publiées pour All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements
6 fiches
My Sticky Elements <= 2.3.3 – Missing Authorization to Authenticated (Subscriber+) Arbitrary Bulk Lead Deletion
The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function…
*-2.3.3
2.3.4
31/12/2025
My Sticky Elements <= 2.3.3 – Missing Authorization
The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs – My Sticky Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all…
*-2.3.3
2.3.4
25/12/2025
All-in-one Floating Contact Form – My Sticky Elements <= 2.1.3 – Missing Authorization
The All-in-one Floating Contact Form – My Sticky Elements plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on an unknown function in versions up to, and including, 2.1.3. This makes it possible…
*-2.1.3
2.1.4
26/12/2023
All-in-one Floating Contact Form <= 2.1.1 – Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings
The All-in-one Floating Contact Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-2.1.1
2.1.2
03/07/2023
My Sticky Elements <= 2.0.8 – Authenticated (Admin+) SQL Injection
The My Sticky Elements plugin for WordPress is vulnerable to SQL Injection via the 'delete_message' parameter in versions up to, and including, 2.0.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on…
2.0.8
2.0.9
09/02/2023
All-in-one Floating Contact Form <= 2.0.3 – Reflected Cross-Site Scripting
The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.
*-2.0.3
2.0.4
10/01/2022
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.