plugin

Rich Web Share Button Vulnerabilities

4 known security issues reported for the Rich Web Share Button WordPress plugin. Most recent disclosed Dec 16, 2024.

1 critical 1 medium

Running Rich Web Share Button on your site? Check whether your installed version is affected.

Scan your site free

Share Buttons – Social Media [rich-web-share-button] <= 1.0.2 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in richteam Share Buttons – Social Media allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through 1.0.2.

Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Dec 16, 2024

CVE-2024-55982 on NVD →

Share Buttons – Social Media <= 1.0.2 - Unauthenticated SQL Injection

critical

The Share Buttons – Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additiona...

CVSS:
9.8
Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Dec 14, 2024

CVE-2024-55982 on NVD →

Share Buttons – Social Media [rich-web-share-button] <= 1.0.2 (unfixed + closed)

unknown

[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Richteam Share Buttons – Social Media allows Blind SQL Injection.This issue affects Share Buttons – Social Media: from n/a through 1.0.2.

Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Nov 11, 2024

CVE-2024-51845 on NVD →

Share Buttons – Social Media <= 1.0.2 - Authenticated (Contributor+) SQL Injection

medium

The Share Buttons – Social Media plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.0.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-lev...

CVSS:
6.5
Affected:
up to 1.0.2
Fix:
No patched version reported
Disclosed:
Nov 8, 2024

CVE-2024-51845 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database