Sticky Side Buttons WordPress Plugin Stored Cross-Site Scripting Vulnerability (CVE-2023-3666) — Low Severity

A security flaw has been found in the Sticky Side Buttons plugin for WordPress, specifically in versions older than 2.0.0. This vulnerability is a type of Stored Cross-Site Scripting (XSS) that could allow malicious code to be embedded into your website. While rated as “Low” severity, it’s important for website administrators to understand and address it promptly.

This particular issue means that a high-privilege user, like an administrator, could inject harmful scripts into the plugin’s settings. These scripts would then execute whenever someone views the affected pages. What makes this noteworthy is that it can happen even on WordPress multisite setups where the “unfiltered_html” option is usually turned off to prevent such attacks.

CVE Details

  • Product: Sticky Side Buttons WordPress plugin
  • Published: September 3, 2025
  • Severity: Low
  • Status: Analyzed

Affected Products

The vulnerability impacts all versions of the Sticky Side Buttons WordPress plugin released before version 2.0.0. If you are running an older version, your website is susceptible to this issue.

Current Status

This vulnerability, identified as CVE-2023-3666, has been thoroughly analyzed. Details regarding its nature and impact are publicly available, allowing users to take necessary protective measures.

Severity Level

This Stored Cross-Site Scripting vulnerability holds a Low severity rating with a CVSS score of 3.5. The primary reason for this rating is that exploitation requires a high-privilege user, such as an administrator. In essence, an attacker would already need significant access to your WordPress site to leverage this flaw, reducing its overall risk compared to vulnerabilities exploitable by lower-privileged users or unauthenticated attackers.

Possible Solutions

To secure your WordPress website against this Stored XSS vulnerability, the most effective solution is to update the Sticky Side Buttons plugin to version 2.0.0 or later. This updated version includes the necessary fixes to properly sanitize and escape settings, preventing the injection of malicious scripts. Always ensure your plugins are kept up-to-date to protect against known security vulnerabilities.

References

https://wpscan.com/vulnerability/c37f1708-c154-41dc-9079-3230827eed1b/

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.