
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Security & Risk Analysis
wordpress.org/plugins/experto-cta-widgetExperto CTA Widget is a lightweight, easy-to-use plugin that comes with lots of customization options and create a popup widget with some contact form …
Is Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Safe to Use in 2026?
Generally Safe
Score 99/100Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "experto-cta-widget" v1.2.1 plugin exhibits a mixed security posture. While it demonstrates good practices such as exclusively using prepared statements for SQL queries and a very high rate of output escaping, several concerning areas exist. The primary weakness lies in its attack surface, with 4 out of 5 AJAX handlers lacking authorization checks. This creates a significant vulnerability if these handlers perform sensitive operations that can be triggered by unauthenticated users. The taint analysis, though small in scope, did reveal two flows with unsanitized paths, which could potentially be exploited if they interact with sensitive data or operations, although no critical or high severity issues were found in this area.
The vulnerability history shows one past CVE, which was of medium severity and is now patched. The common vulnerability type being 'Missing Authorization' is a direct red flag that aligns with the static analysis findings of unprotected AJAX handlers. This history suggests a recurring issue with access control within the plugin's development, underscoring the importance of thoroughly securing all entry points. In conclusion, the plugin has strengths in data handling and output sanitization, but the significant number of unprotected AJAX endpoints and the historical pattern of authorization flaws represent considerable risks that need immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Past medium severity vulnerability
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin <= 1.1.1 - Missing Authorization to Unauthenticated Settings Update
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Code Analysis
Output Escaping
Data Flow Analysis
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Attack Surface
AJAX Handlers 5
WordPress Hooks 11
Maintenance & Trust
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Alternatives
Boxzilla – Pop-Ups for WordPress
boxzilla
Flexible pop-ups or slide-ins, showing up at just the right time.
Widget Pack
ts-widget-pack
Widget Pack is a WordPress plugin that enables essential, yet powerful features for your website.
Button Widget
button-widget
A simple customizable button widget for your sidebars.
Call to Action Widget
call-to-action-widget
A simple text widget with Title, Image URL, A text/html area, Link Text and Link URL. This simple widget is often used for a call to action widget.
PopPop
poppop
Easily display your widgets inside modal and popup windows.
Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin Developer Profile
4 plugins · 170 total installs
How We Detect Experto CTA Widget – Call To Action, Sticky CTA, Floating Button Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/experto-cta-widget/css/esc-admin.css/wp-content/plugins/experto-cta-widget/js/esc-admin.jsexperto-cta-widget/css/esc-admin.css?ver=experto-cta-widget/js/esc-admin.js?ver=HTML / DOM Fingerprints
review-noticereview-top-barreview-inneresc-col100esc-col-innerstarfa-starreview-btnid="escstyle"id="esc_box_primary_color"id="esc_box_secondary_color"id="esc_box_text_color"id="esc_box_icon_color"id="esc_box_footer_icon_color"EscURLS