Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical0
High0
Medium2
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-01-02

CVE-2025-14428 - Mystickyelements Plugin

The All-in-one Sticky Floating Contact Form, Call, Click to Chat, and 50+ Social Icon Tabs - My Sticky Elements plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'my_sticky_elements_bulks' function in all versions up to, and including, 2.3.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete all contact form leads stored by the plugin.

PLUGIN Mystickyelements

CVE-2025-14428

MEDIUM CVSS 4.3 2026-01-01
Threat Entry Updated 2024-11-21

CVE-2022-0148 - Mystickyelements Plugin

The All-in-one Floating Contact Form, Call, Chat, and 50+ Social Icon Tabs WordPress plugin before 2.0.4 was vulnerable to reflected XSS on the my-sticky-elements-leads admin page.

PLUGIN Mystickyelements

CVE-2022-0148

MEDIUM CVSS 5.4 2022-02-07
Scroll to top