CVE-2026-15383
Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.
| Vendor | unknown |
| Product | blog floating button |
| Published | Aug 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown blog floating button
Be the first to know when new unknown vulnerabilities affecting unknown blog floating button are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Blog Floating Button
0 โค 1.4.20
References
Credits
Shivamani Vastrala WPScan