A security flaw has been found in the Sticky Side Buttons plugin for WordPress, specifically in versions older than 2.0.0. This vulnerability is a type of Stored Cross-Site Scripting (XSS) that could allow malicious code to be embedded into your website. While rated as “Low” severity, it’s important for website administrators to understand and address it promptly.
This particular issue means that a high-privilege user, like an administrator, could inject harmful scripts into the plugin’s settings. These scripts would then execute whenever someone views the affected pages. What makes this noteworthy is that it can happen even on WordPress multisite setups where the “unfiltered_html” option is usually turned off to prevent such attacks.
CVE Details
- Product: Sticky Side Buttons WordPress plugin
- Published: September 3, 2025
- Severity: Low
- Status: Analyzed
Affected Products
The vulnerability impacts all versions of the Sticky Side Buttons WordPress plugin released before version 2.0.0. If you are running an older version, your website is susceptible to this issue.
Current Status
This vulnerability, identified as CVE-2023-3666, has been thoroughly analyzed. Details regarding its nature and impact are publicly available, allowing users to take necessary protective measures.
Severity Level
This Stored Cross-Site Scripting vulnerability holds a Low severity rating with a CVSS score of 3.5. The primary reason for this rating is that exploitation requires a high-privilege user, such as an administrator. In essence, an attacker would already need significant access to your WordPress site to leverage this flaw, reducing its overall risk compared to vulnerabilities exploitable by lower-privileged users or unauthenticated attackers.
Possible Solutions
To secure your WordPress website against this Stored XSS vulnerability, the most effective solution is to update the Sticky Side Buttons plugin to version 2.0.0 or later. This updated version includes the necessary fixes to properly sanitize and escape settings, preventing the injection of malicious scripts. Always ensure your plugins are kept up-to-date to protect against known security vulnerabilities.
References
https://wpscan.com/vulnerability/c37f1708-c154-41dc-9079-3230827eed1b/


