
CVE-2026-15383 The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauthenticated trackin… https://www.cve.org/CVERecord?id=CVE-2026-15383
Post summary
The notice provides a technical disclosure of an unsanitized User‑Agent header stored by the Blog Floating Button WordPress plugin. It does not mention exploitation, patches, or mitigations.

