Add Social Share Buttons for Whatsapp and Viber < 1.1 - Cross-Site Request Forgery

2018-05-30 00:00
ThreatPress

Strategic Overview

Status
Patched in 1.1
Affected Version< 1.1
CVSS6.5Medium
CVECVE-2018-11632
View all Add Social Share Buttons for Whatsapp and Viber vulnerabilities

Vulnerability Overview

An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php CSRF. There's no nonce or capability check in the whatsapp_share_setting_add_update() function.

Technical Analysis

REMEDIATION: Update to version 1.1, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C