Unrated severityNVD Advisory· Published Aug 3, 2026· Updated Aug 3, 2026
Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
CVE-2026-15383
Description
The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated tracking REST endpoint and later renders unescaped in an administrator report page. This allows an unauthenticated attacker to store a malicious script that executes in the session of any administrator who views the access report, leading to site takeover.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=1.4.20
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/45e5d74e-6f7b-499b-ae25-74fe1bc8d18d/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.