Better Click To Tweet <= 5.10.3 - Cross-Site Request Forgery
high
The Better Click To Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.10.3. This is due to missing or incorrect nonce validation on the welcome_page function. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted...
- CVSS:
- 8.8
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.4
- Disclosed:
- Nov 28, 2022
Better Click To Tweet <= 5.10.3 - Missing Authorization
medium
The Better Click To Tweet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the welcome_page function in versions up to, and including, 5.10.3. This makes it possible for unauthenticated attackers to update some of the plugin's settings.
- CVSS:
- 6.5
- Affected:
- up to 5.10.3
- Fixed in:
- 5.10.4
- Disclosed:
- Nov 28, 2022
CVE-2022-45839 on NVD →
Better Click To Tweet [better-click-to-tweet] < 5.10.4
unknown
The Better Click To Tweet plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.10.3. This is due to missing or incorrect nonce validation on the welcome_page function. This makes it possible for unauthenticated attackers to invoke this function, via forged request granted...
- Affected:
- up to 5.10.4
- Fixed in:
- 5.10.4
- Disclosed:
- Nov 28, 2022
Better Click To Tweet [better-click-to-tweet] < 5.10.4
unknown
The Better Click To Tweet plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the welcome_page function in versions up to, and including, 5.10.3. This makes it possible for unauthenticated attackers to update some of the plugin's settings.
- Affected:
- up to 5.10.4
- Fixed in:
- 5.10.4
- Disclosed:
- Nov 28, 2022
Better Click To Tweet <= 5.10.1 - Reflected Cross-Site Scripting
medium
The Better Click To Tweet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping on the $_SERVER['REQUEST_URI'] value. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- CVSS:
- 6.1
- Affected:
- up to 5.10.1
- Fixed in:
- 5.10.2
- Disclosed:
- Apr 27, 2022
Better Click To Tweet [better-click-to-tweet] <= 5.10.1
unknown
Reflected Cross-Site Scripting (XSS) vulnerability discovered in WordPress Better Click To Tweet plugin (versions <= 5.10.1).
- Affected:
- up to 5.10.1
- Fixed in:
- 5.10.1
- Disclosed:
- Apr 27, 2022
Better Click To Tweet [better-click-to-tweet] < 5.10.2
unknown
The Better Click To Tweet plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.10.1 due to insufficient input sanitization and output escaping on the $_SERVER['REQUEST_URI'] value. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in...
- Affected:
- up to 5.10.2
- Fixed in:
- 5.10.2
- Disclosed:
- Apr 27, 2022
Better Click To Tweet [better-click-to-tweet] < 5.10.4
unknown
Update the WordPress Better Click To Tweet plugin to the latest available version (at least 5.10.4).
Tien Nguyen Anh discovered and reported this Broken Access Control vulnerability in WordPress Better Click To Tweet Plugin. This vulnerability has been fixed in version 5.10.4.
- Affected:
- up to 5.10.4
- Fixed in:
- 5.10.4
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database