WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons <= 1.7.0 - Missing Authorization to Unauthenticated Sticky Status Update

CVE Details

Basic Information

Title WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons <= 1.7.0 - Missing Authorization to Unauthenticated Sticky Status Update
Type cve
Published 2025-08-02T07:24:21.531Z
Modified 2025-08-02T07:24:21.531Z

Product Information

Vendor blendmedia
Product WP CTA
Version *

CVSS Information

Base Score 5.3 (MEDIUM)
Attack Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

AI Analysis

AI Description The WP CTA plugin for WordPress is vulnerable to unauthorized data modification due to missing capability checks, allowing attackers to alter sticky status and display names without authentication.
AI Severity Medium
AI Vendor blendmedia
AI Product WP CTA – Call To Action Plugin
AI Version 1.7.0

Affected Products

  • blendmedia WP CTA *

Additional Information

CWE List CWE-862
Source Wordfence

Description

The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘update_cta_status’ and ‘change_sticky_sidebar_name’ functions in all versions up to, and including, 1.7.0. This makes it possible for unauthenticated attackers to update the status of a sticky and update the name displayed in the back-end WP CTA Dashboard.

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.