plugin

Better Click To Tweet Vulnerabilities

8 known security issues reported for the Better Click To Tweet WordPress plugin. Most recent disclosed Nov 28, 2022.

1 high 2 medium

Running Better Click To Tweet on your site? Check whether your installed version is affected.

Scan your site free

Better Click To Tweet <= 5.10.3 - Cross-Site Request Forgery

high

The Better Click To Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.10.3. This is due to missing or incorrect nonce validation on the welcome_page function. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted...

CVSS:
8.8
Affected:
up to 5.10.3
Fixed in:
5.10.4
Disclosed:
Nov 28, 2022

Better Click To Tweet <= 5.10.3 - Missing Authorization

medium

The Better Click To Tweet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the welcome_page function in versions up to, and including, 5.10.3. This makes it possible for unauthenticated attackers to update some of the plugin's settings.

CVSS:
6.5
Affected:
up to 5.10.3
Fixed in:
5.10.4
Disclosed:
Nov 28, 2022

CVE-2022-45839 on NVD →

Better Click To Tweet [better-click-to-tweet] < 5.10.4

unknown

The Better Click To Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.10.3. This is due to missing or incorrect nonce validation on the welcome_page function. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted...

Affected:
up to 5.10.4
Fixed in:
5.10.4
Disclosed:
Nov 28, 2022

Better Click To Tweet [better-click-to-tweet] < 5.10.4

unknown

The Better Click To Tweet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the welcome_page function in versions up to, and including, 5.10.3. This makes it possible for unauthenticated attackers to update some of the plugin's settings.

Affected:
up to 5.10.4
Fixed in:
5.10.4
Disclosed:
Nov 28, 2022

Better Click To Tweet <= 5.10.1 - Reflected Cross-Site Scripting

medium

The Better Click To Tweet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping on the $_SERVER['REQUEST_URI'] value. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

CVSS:
6.1
Affected:
up to 5.10.1
Fixed in:
5.10.2
Disclosed:
Apr 27, 2022

Better Click To Tweet [better-click-to-tweet] <= 5.10.1

unknown

Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Better Click To Tweet plugin (versions <= 5.10.1).

Affected:
up to 5.10.1
Fixed in:
5.10.1
Disclosed:
Apr 27, 2022

Better Click To Tweet [better-click-to-tweet] < 5.10.2

unknown

The Better Click To Tweet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping on the $_SERVER['REQUEST_URI'] value. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...

Affected:
up to 5.10.2
Fixed in:
5.10.2
Disclosed:
Apr 27, 2022

Better Click To Tweet [better-click-to-tweet] < 5.10.4

unknown

Update the WordPress Better Click To Tweet plugin to the latest available version (at least 5.10.4). Tien Nguyen Anh discovered and reported this Broken Access Control vulnerability in WordPress Better Click To Tweet Plugin. This vulnerability has been fixed in version 5.10.4.

Affected:
up to 5.10.4
Fixed in:
5.10.4

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database