Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php.
We have discovered 36 live websites that are affected by CVE-2015-5528.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 36 live websites (100% of Floating Social Bar install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 0 versions ( less than 0.1% of all versions) |
| 18 websites | |
| 4 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites | |
| 1 websites |
| .com | 18 websites |
| .ca | 2 websites |
| .net | 2 websites |
| .org | 2 websites |
| .ch | 1 websites |
| .com.au | 1 websites |
| .de | 1 websites |
| .es | 1 websites |
| .fr | 1 websites |
| .info | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | *,***,*** | ||
| ******.ro | *,***,*** | ||
| *********.ro | *,***,*** | ||
| **********.pl | *,***,*** | ||
| **********.com | *,***,*** | ||
| **********.com | **,***,*** | ||
| *****.net | **,***,*** | ||
| ***********.******.de | **,***,*** | ||
| **********************.com | **,***,*** | ||
| **********.com | **,***,*** |
FAQ