Social Share Buttons by Supsystic <= 2.2.3 - Cross-Site Request Forgery to Settings Update

2022-06-01 00:00
Daniel Ruf

Strategic Overview

Status
Patched in 2.2.4
Affected Version<= 2.2.3
CVSS8.8High
CVECVE-2022-1653
View all Social Share Buttons by Supsystic vulnerabilities

Vulnerability Overview

The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.

Technical Analysis

REMEDIATION: Update to version 2.2.4, or a newer patched version --- IDENTIFIER: CWE-352 (Cross-Site Request Forgery (CSRF)) The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C