Really Simple Facebook Twitter Share Buttons < 2.10.5 - Cross-Site Request Forgery
mediumThe Really Simple Facebook Twitter Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions before 2.10.5. This is due to missing or incorrect nonce validation on the really_simple_share_settings function. This makes it possible for unauthenticated attackers to modify the settings page...
- CVSS:
- 6.3
- Affected:
- up to 2.10.5
- Fixed in:
- 2.10.5
- Disclosed:
- Aug 1, 2014