CVE-2024-5226

Published
View on NVD ↗
CVSS v3
6.4
MEDIUM
CVSS v2
N/A
Affected
1
PROJECT

Description

The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions up to, and including, 5.4.10 due to insufficient validation of SVG files. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

<p>Fuse Social Floating Sidebar allow you to insert social media links very easily, you can show social media icons as floating on the website. This plugin provides very attractive interface which allows you to make settings for those social media icons, in the means of :</p> <ul> <li>Type of icons round and square</li> <li> Animated Rotation Effect in Icons.</li> <li>Shadow in icons.</li> <li>Different size of social icons.</li> </ul> <p>You can check live demo with all features as well :<br /> <strong>Fuse Social </strong> <a href="https://www.fusefloat.com/demo/" title="Fuse Social Floating" rel="nofollow ugc">Demo</a></p> <p>Control Visibility on Scroll</p> <h3></h3> <blockquote> <p>This new feature allows you to show the social icons when a user scrolls on the page. It helps to prevent displaying social icons on the main hero section of the page, and when the user scrolls, these social icons pop up.</p> </blockquote> <p>Action Button Feature</p> <h3></h3> <blockquote> <p>Now, you can display social icons under the action button, so you need to click on the action button to view the social icon</p> </blockquote> <p>Sticky Social Icons</p> <h3></h3> <blockquote> <p>Floating social icons with custom colors allow you to match the design icons according to your site.</p> </blockquote> <p></p> <p>Pro Version</p> <h3></h3> <p>Fuse Pro allow you to add custom icons, and give you more control on the social icon visiblity and analytics as well. Pro version includes following features as well.</p> <ul> <li>Upload icon as image or select from icons library.</li> <li> Conditional settings, allow you to remove the social sidebar from specific pages.</li> <li>Analytics feature provides you interface so you can view which social icon is getting more clicks.</li> <li>Allow you to re-arrange the icons. </li> <li>Change vertical position of the icons.</li> <li>Get access to more icon designs.</li> <li>24/7 Lifetime support and updates with unlimited websites.</li> <li>and much much more!</li> </ul> <p><a href="https://www.fusefloat.com" title="Fuse Social Floating" rel="nofollow ugc">Get Pro Version Now</a></p> <p>Use coupon code WPORG20 to get 20% discount.<br /> <br /> <span class="embed-youtube" style="text-align:center; display: block;"><iframe loading="lazy" class="youtube-player" width="750" height="422" src="https://www.youtube.com/embed/fBC0SL5Ieig?version=3&#038;rel=1&#038;showsearch=0&#038;showinfo=1&#038;iv_load_policy=1&#038;fs=1&#038;hl=en-US&#038;autohide=2&#038;wmode=transparent" allowfullscreen="true" style="border:0;" sandbox="allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox"></iframe></span><br /> It&#8217;s simple, unique, and the best WordPress plugin for floating social icons.<br /> Fuse Social Floating Sidebar allows you to add the following social icons to your website <br /> * Facebook<br /> * Threads (New)<br /> * X (New)<br /> * RSS<br /> * YouTube<br /> * LinkedIn<br /> * Flickr<br /> * Pinterest<br /> * StumbleUpon<br /> * Google Plus<br /> * Instagram<br /> * Tumblr<br /> * Vine<br /> * SoundCloud<br /> * VK<br /> * Reddit<br /> * Stack OverFlow<br /> * Behance<br /> * Github<br /> and many more..</p>
WordPress Plugin DirectoryWordPress Plugin Directory
395K