AddThis <= 5.0.12 - Cross-Site Scripting
medium
The AddThis plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 5.0.12 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 5.0.13
- Fixed in:
- 5.0.13
- Disclosed:
- Aug 11, 2015
AddThis Sharing Buttons <= 5.0.12 - Authenticated Cross-Site Scripting
medium
The addthis plugin before 5.0.13 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=addthis_social_widget pubid parameter.
- CVSS:
- 4.8
- Affected:
- up to 5.0.13
- Fixed in:
- 5.0.13
- Disclosed:
- Aug 11, 2015
CVE-2015-9439 on NVD →
AddThis <= 5.0.2 - Authenticated Stored Cross-Site Scripting
medium
The AddThis plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘at_async_loading’ AJAX action in versions up to, and including, 5.0.2 due to insufficient input sanitization and output escaping. This makes it possible for Subscriber-level attackers to inject arbitrary web scripts in pages that wil...
- CVSS:
- 6.4
- Affected:
- up to 5.0.3
- Fixed in:
- 5.0.3
- Disclosed:
- Jun 10, 2015
WordPress Share Buttons Plugin – AddThis < 2.2.0 - Code Injection
critical
The WordPress Share Buttons Plugin – AddThis for WordPress is vulnerable to code injection in versions up to, and including, 2.1.3. This is due to a backdoor vulnerability. This makes it possible for attackers to execute arbitrary code via the plugin.
- CVSS:
- 9.8
- Affected:
- up to 2.2.0
- Fixed in:
- 2.2.0
- Disclosed:
- Jun 21, 2011
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database