plugin

Sharebar Vulnerabilities

13 known security issues reported for the Sharebar WordPress plugin. Most recent disclosed Jul 11, 2022.

1 critical 1 high 2 medium

Running Sharebar on your site? Check whether your installed version is affected.

Scan your site free

Sharebar [sharebar] <= 1.4.1 (unfixed + closed)

unknown

[en] The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them

Affected:
up to 1.4.1
Fix:
No patched version reported
Disclosed:
Jul 11, 2022

CVE-2022-1626 on NVD →

Sharebar <= 1.4.1 - Cross-Site Request Forgery to Settings Update & Cross-Site Scripting

high

The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them

CVSS:
8.8
Affected:
up to 1.4.1
Fix:
No patched version reported
Disclosed:
Jun 15, 2022

CVE-2022-1626 on NVD →

Sharebar [sharebar] < 1.2.2 (closed)

unknown

[en] The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Aug 28, 2019

CVE-2012-6718 on NVD →

Sharebar [sharebar] < 1.2.2 (closed)

unknown

[en] The sharebar plugin before 1.2.2 for WordPress has SQL injection.

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
Aug 28, 2019

CVE-2012-6719 on NVD →

Sharebar [sharebar] < 1.2.6 (closed)

unknown

This plugin is prone to sharebar-admin.php page parameter cross site scripting vulnerability Update the plugin.

Affected:
up to 1.2.6
Fixed in:
1.2.6
Disclosed:
May 15, 2015

Sharebar [sharebar] < 1.2.4 (closed)

unknown

This plugin is prone to wp-admin/options-general.php status parameter cross site scripting vulnerability. Update the plugin.

Affected:
up to 1.2.4
Fixed in:
1.2.4
Disclosed:
May 15, 2015

Sharebar <= 1.4.2 - Cross-Site Scripting

medium

Multiple cross-site request forgery (CSRF) vulnerabilities in the Sharebar plugin 1.4.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) modify buttons, or (3) insert cross-site scripting (XSS) sequences.

CVSS:
6.1
Affected:
up to 1.4.2
Fixed in:
1.4.3
Disclosed:
Sep 24, 2013

CVE-2013-3491 on NVD →

Sharebar [sharebar] < 1.4.3 (closed)

unknown

[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the Sharebar plugin 1.2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) modify buttons, or (3) insert cross-site scripting (XSS) sequences.

Affected:
up to 1.4.3
Fixed in:
1.4.3
Disclosed:
Jul 16, 2013

CVE-2013-3491 on NVD →

Sharebar <= 1.2.1 - SQL Injection

critical

The sharebar plugin before 1.2.2 for WordPress has SQL injection via id parameter.

CVSS:
9.8
Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
May 15, 2012

CVE-2012-6719 on NVD →

Sharebar <= 1.2.1 - Cross-Site Scripting

medium

The Sharebar plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.

CVSS:
6.1
Affected:
up to 1.2.1
Fixed in:
1.2.2
Disclosed:
May 15, 2012

CVE-2012-6718 on NVD →

Sharebar [sharebar] < 1.2.2 (closed)

unknown

Sharebar plugin is prone to multiple cross-site scripting and SQL-injection vulnerabilities because of failure to properly clean up user-supplied input. It allows an attacker to steal cookie-based authentication credentials, access or modify data, compromise the application or exploit latent vulnerabilities in the unde...

Affected:
up to 1.2.2
Fixed in:
1.2.2
Disclosed:
May 15, 2012

Sharebar [sharebar] < 1.2.2 (closed)

unknown

The Sharebar WordPress plugin was affected by a SQL Injection &amp; Cross Site Scripting security vulnerability.

Affected:
up to 1.2.2
Fixed in:
1.2.2

Sharebar [sharebar] < 1.4.1 (closed)

unknown

sharebar-admin.php page Parameter XSS

Affected:
up to 1.4.1
Fixed in:
1.4.1

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database