PT-2023-12473 · WordPress · Kiwi Social Share

Jerome Bruandet

·

Published

2023-06-07

·

Updated

2023-06-13

·

CVE-2021-4362

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kiwi Social Share plugin for WordPress version 2.1.0
Description The issue is related to an authorization bypass due to a missing capability check on the kiwi social share get option() function, which is called via the "kiwi social share get option" AJAX action. This allows unauthenticated attackers to read and modify arbitrary options, potentially leading to a complete site takeover. The vulnerability was previously fixed but was reintroduced in version 2.1.0.
Recommendations For Kiwi Social Share plugin for WordPress version 2.1.0, consider disabling the kiwi social share get option() function until a patch is available to prevent exploitation. Restrict access to the "kiwi social share get option" AJAX action to minimize the risk of unauthorized option modifications. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-4362

Affected Products

Kiwi Social Share