AddToAny Share Buttons <= 1.7.47 - Authenticated Stored Cross-Site Scripting
medium
The AddToAny Share Buttons WordPress plugin before 1.7.48 does not escape its Image URL button setting, which could lead allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
- CVSS:
- 4.8
- Affected:
- up to 1.7.48
- Fixed in:
- 1.7.48
- Disclosed:
- Aug 10, 2021
CVE-2021-24616 on NVD →
AddToAny Share Buttons <= 1.7.45 - Authenticated Stored Cross-Site Scripting
medium
The AddToAny Share Buttons WordPress plugin before 1.7.46 does not sanitise its Sharing Header setting when outputting it in frontend pages, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
- CVSS:
- 5.4
- Affected:
- up to 1.7.46
- Fixed in:
- 1.7.46
- Disclosed:
- Aug 9, 2021
CVE-2021-24568 on NVD →
AddToAny Share Buttons <= 1.7.14 - HTTP Host Header Injection
medium
The AddToAny Share Buttons plugin for WordPress is vulnerable to Host Header Injections in versions up to, and including, 1.7.14. This is due to a failure to properly validate the HTTP request header. This makes it possible for unauthorized attackers to poison the website cache and log users credentials.
- CVSS:
- 4.7
- Affected:
- up to 1.7.14
- Fixed in:
- 1.7.15
- Disclosed:
- Aug 16, 2017
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database