Float to Top Button Stored Cross-Site Scripting Vulnerability (CVE-2022-2709) — Medium Severity

The “Float to Top Button” is a popular WordPress plugin designed to add a convenient scroll-to-top button to websites, enhancing user experience. However, a significant security flaw has been discovered in versions up to and including 2.3.6. This vulnerability, identified as a Stored Cross-Site Scripting (XSS) issue, could allow attackers with high-level access, such as administrators, to inject harmful code into your website. What makes this particularly concerning is that the attack could occur even when WordPress’s built-in `unfiltered_html` capability is restricted, a common security measure in multi-site installations.

In simple terms, certain settings within the plugin do not properly clean up user-supplied data. If a malicious administrator (or an attacker who has compromised an admin account) inputs harmful scripts into these settings, the scripts get saved. When someone else views these affected settings pages, the malicious code executes in their browser. This could lead to various attacks, including stealing session cookies, defacing the website, or redirecting users to malicious sites.

CVE Details

Product: Float to Top Button WordPress Plugin
CVE ID: CVE-2022-2709
Published Date: September 19, 2022
Severity: Medium (CVSS Score 4.8)
Status: Analyzed

Affected Products

The Stored Cross-Site Scripting vulnerability impacts the following versions of the Float to Top Button WordPress plugin:

  • Float to Top Button WordPress Plugin versions up to and including 2.3.6.

If you are using any of these versions, your website is potentially at risk.

Current Status

This vulnerability has been thoroughly analyzed. As of the latest information, there is no official patch or updated version available to fix this specific issue within the Float to Top Button plugin. This means users of affected versions remain exposed to the risk of XSS attacks.

Severity Level

Rated as “Medium” severity with a CVSS Score of 4.8, this vulnerability poses a notable threat. While it requires high-privilege access (like an administrator account) to exploit, the impact can be significant. Stored XSS attacks can compromise user sessions, lead to website defacement, or facilitate further malicious activities on the affected site. In a multi-site environment, where `unfiltered_html` is often disabled to prevent such injections, this bypass makes the vulnerability even more critical.

Possible Solutions

Given that no direct fix or patch has been released for the Float to Top Button plugin (as indicated by the “No known fix” status), immediate action is crucial to protect your WordPress site:

  1. Disable or Uninstall: The most effective immediate mitigation is to disable or completely uninstall the Float to Top Button plugin from your WordPress installation.
  2. Seek Alternatives: Look for alternative scroll-to-top plugins that are actively maintained and have a strong security track record. Ensure any new plugin you install is regularly updated and reviewed for security vulnerabilities.
  3. Monitor for Updates: Keep an eye on the official plugin repository or the developer’s website for any future security advisories or patched versions. If an update becomes available, apply it immediately after thorough testing in a staging environment.

Regular security audits of your WordPress plugins and themes are always recommended to minimize exposure to such vulnerabilities.

References

https://wpscan.com/vulnerability/1c551234-9c59-41a0-ab74-beea2d27df6b

https://wpscan.com/vulnerability/1c551234-9c59-41a0-ab74-beea2d27df6b

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.