CVE-2025-46451

WordPress Floating Social Bar <= 1.1.7 - Cross Site Scripting (XSS) Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Syed Balkhi Floating Social Bar allows Stored XSS. This issue affects Floating Social Bar: from n/a through 1.1.7.


We have discovered 716 live websites that are affected by CVE-2025-46451.

Run a Free Instant Scan




Affected Software

Product  Floating Social Bar
Category Wordpress Plugins
Vulnerable Domains716 live websites (100% of Floating Social Bar install base)
Vulnerable Versions
  • from 0 through 1.1.7
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Apr 24, 2025
  • Updated - Apr 24, 2025

Credits

  • Nabil Irawan (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-46451
United States351 websites



Germany50 websites
France33 websites
Vietnam32 websites
GB30 websites
Netherlands25 websites
Spain18 websites
Sweden16 websites
Italy14 websites
Canada13 websites

Website Distribution by TLD

Number of websites using CVE-2025-46451
.com405 websites
.org43 websites
.net38 websites
.de25 websites
.nl16 websites
.es14 websites
.se12 websites
.co.uk10 websites
.it9 websites
.info9 websites

Websites affected by CVE-2025-46451

Top websites that are affected by CVE-2025-46451. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.********.com United States***,***
****************.com United States***,***
********.com Germany***,***
**********.com United States***,***
******.co United States***,***
*********.com United States***,***
**************.com United States***,***
****************.com United States***,***
*********.com United States***,***
*******************.com ***,***
See full domain list

FAQ

CVE-2025-46451 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Floating Social Bar
A total of 716 websites have been identified as vulnerable to CVE-2025-46451, based on global website indexing conducted by WebTechSurvey.
The Floating Social Bar is affected by the CVE-2025-46451 vulnerability.
Floating Social Bar versions up to and including 1.1.7 are vulnerable to CVE-2025-46451.