Unrated severityNVD Advisory· Published Jul 29, 2022· Updated Apr 28, 2026
WordPress Floating Div plugin <= 3.0 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability
CVE-2022-36378
Description
Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in PluginlySpeaking Floating Div plugin <= 3.0 at WordPress.
Affected products
1- Range: <= 3.0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- patchstack.com/database/vulnerability/floating-div/wordpress-floating-div-plugin-3-0-authenticated-stored-cross-site-scripting-xss-vulnerabilitymitrex_refsource_CONFIRM
- wordpress.org/plugins/floating-div/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.