cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,poc,trended,trended_no_1,published,trended_score CVE-2023-7048,https://securityvulnerability.io/vulnerability/CVE-2023-7048,Cross-Site Request Forgery Risk in My Sticky Bar Plugin for WordPress,"The My Sticky Bar plugin for WordPress is exposed to a Cross-Site Request Forgery vulnerability due to inadequate nonce validation in the mystickymenu-contact-leads.php file. All versions up to and including 2.6.6 are affected. This flaw allows unauthorized attackers to exploit the system by tricking a legitimate site administrator into executing a malicious action, such as clicking on an infected link. When executed, the attack can trigger the export of a CSV file containing sensitive contact lead information to a publicly accessible location, where it can be retrieved shortly before automatic deletion occurs. This vulnerability highlights the critical importance of implementing proper security measures to protect sensitive data from unauthorized access.",Wordpress,"Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any Theme – My Sticky Bar (formerly myStickymenu)",4.3,MEDIUM,0.0005099999834783375,false,,false,false,false,,false,false,2024-01-11T08:32:55.514Z,0