AddToAny Share Buttons <= 1.7.14 - HTTP Host Header Injection

2017-08-16 00:00
Paul Dannewitz

Strategic Overview

Status
Patched in 1.7.15
Affected PluginAddToAny Share Buttons
Affected Version<= 1.7.14
CVSS4.7Medium
CVEN/A
View all AddToAny Share Buttons vulnerabilities

Vulnerability Overview

The AddToAny Share Buttons plugin for WordPress is vulnerable to Host Header Injections in versions up to, and including, 1.7.14. This is due to a failure to properly validate the HTTP request header. This makes it possible for unauthorized attackers to poison the website cache and log users credentials.

Technical Analysis

REMEDIATION: Update to version 1.7.15, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C

AddToAny Share Buttons <= 1.7.14 - HTTP Host Header Injection