Description
WordPress Plugin Floating Social Media Links is prone to multiple remote file include vulnerabilities because it fails to sufficiently sanitize user-supplied input. Exploiting these issues may allow an attacker to compromise the application and the underlying system; other attacks are also possible. WordPress Plugin Floating Social Media Links version 1.4.2 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.4.3 or latest
References
Related Vulnerabilities
WordPress Plugin WP-Live Chat by 3CX Cross-Site Scripting (8.1.9)
WordPress Plugin Easy WP SMTP PHP Object Injection (1.3.9)
WordPress Plugin RSVPMaker SQL Injection (9.3.2)
WordPress Plugin Form Store to DB Unspecified Vulnerability (1.1.0)
WordPress Plugin Fancy Gallery Cross-Site Scripting (1.5.12)