PT-2024-39234 · WordPress · Share This Image

Krzysztof Zając

·

Published

2024-09-17

·

Updated

2024-09-27

·

CVE-2024-8761

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Share This Image plugin for WordPress versions up to, and including, 2.03
Description: The issue is due to insufficient validation on the redirect url supplied via the link parameter. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Recommendations: For versions up to, and including, 2.03, consider disabling the plugin until a patch is available to prevent potential redirects to malicious sites. As a temporary workaround, restrict the use of the link parameter in the plugin to minimize the risk of exploitation.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2024-8761

Affected Products

Share This Image