Mobile Contact Bar
Mobile Contact Bar has one disclosed vulnerability in the WordSec catalog, all reported in 2025; it is fixed as of September 2026. Their average CVSS score is 5.5, and the most serious one scores 5.5 out of 10.
The most common weakness is Cross-Site Scripting, behind 1 of the records (100%).
The one issue recorded for Mobile Contact Bar has a vendor fix available, so running the current release closes it.
All of these findings were reported by Krugov Artyom. Mobile Contact Bar is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-12739Mobile Contact Bar <= 3.0.4 - Authenticated (Admin+) Stored Cross-Site Scripting
Read the full analysisVulnerability Records

Mobile Contact Bar
Author
Anna Bansaghi
Mobile Contact Bar is a compact and highly customizable plugin, which allows your visitors to contact you directly via mobile phones, or access your site’s pages instantly. The settings page is available under the Settings → Mobile Contact Bar menu in the WordPress dashboard. Features Icons for social media, call-to-actions, or any links to web pages Simple and intuitive styling with the aid of the Real-time Model Built-in icon picker with Font Awesome 6 integration Customizable URLs using query string parameters No data collection from your website’s visitors Super easy to use, no coding required! Special Actions Scroll to Top of the page WooCommerce Cart with Item Counter Supported Protocols http https mailto skype sms tel viber Tested with Twenty Twenty-Four Twenty Twenty-Three Twenty Twenty-Two Twenty Twenty-One Twenty Twenty Twenty Nineteen Twenty Seventeen Twenty Sixteen Twenty Fifteen Twenty Fourteen Twenty Thirteen Twenty Twelve Twenty Eleven Twenty Ten
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C