AddToAny Share Buttons <= 1.7.14 - HTTP Host Header Injection
2017-08-16 00:00
Paul DannewitzStrategic Overview
StatusPatched in 1.7.15
Affected PluginAddToAny Share Buttons
Affected Version
<= 1.7.14CVSS4.7Medium
CVE
N/AVulnerability Overview
The AddToAny Share Buttons plugin for WordPress is vulnerable to Host Header Injections in versions up to, and including, 1.7.14. This is due to a failure to properly validate the HTTP request header. This makes it possible for unauthorized attackers to poison the website cache and log users credentials.
Technical Analysis
REMEDIATION: Update to version 1.7.15, or a newer patched version --- IDENTIFIER: CWE-20 (Improper Input Validation) The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C