PT-2022-14025 · WordPress · Social Share Buttons By Supsystic

Daniel Ruf

·

Published

2022-06-27

·

Updated

2022-07-07

·

CVE-2022-1653

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Social Share Buttons by Supsystic WordPress plugin versions prior to 2.2.4
Description The issue allows an attacker to trick logged-in users into manipulating or changing plugin settings, as well as creating, deleting, and renaming projects and networks, due to the lack of CSRF checks in its ajax endpoints and admin pages.
Recommendations For versions prior to 2.2.4, update to version 2.2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the plugin's admin pages and ajax endpoints to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-1653

Affected Products

Social Share Buttons By Supsystic