WP Sticky Button <= 1.4 - Missing Authorization to Arbitrary Settings Update

2022-08-01 00:00
Krzysztof Zając

Strategic Overview

Status
Patched in 1.4.1
Affected Version<= 1.4
CVSS6.3Medium
CVECVE-2022-2375
View all WP Sticky Button – Click to Chat vulnerabilities

Vulnerability Overview

The WP Sticky Button plugin for WordPress is vulnerable to unauthenticated plugin settings update in versions up to, and including, 1.4, due to missing authorization on the okapi_wasb_save_settings AJAX action. This allows unauthenticated attackers to update arbitrary plugin settings.

Technical Analysis

REMEDIATION: Update to version 1.4.1, or a newer patched version --- IDENTIFIER: CWE-862 (Missing Authorization) The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C