Sharebar [sharebar] <= 1.4.1 (unfixed + closed)
unknown
[en] The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them
- Affected:
- up to 1.4.1
- Fix:
- No patched version reported
- Disclosed:
- Jul 11, 2022
CVE-2022-1626 on NVD →
Sharebar <= 1.4.1 - Cross-Site Request Forgery to Settings Update & Cross-Site Scripting
high
The Sharebar WordPress plugin through 1.4.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and also lead to Stored Cross-Site Scripting issue due to the lack of sanitisation and escaping in some of them
- CVSS:
- 8.8
- Affected:
- up to 1.4.1
- Fix:
- No patched version reported
- Disclosed:
- Jun 15, 2022
CVE-2022-1626 on NVD →
Sharebar [sharebar] < 1.2.2 (closed)
unknown
[en] The sharebar plugin before 1.2.2 for WordPress has XSS, a different issue than CVE-2013-3491.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Aug 28, 2019
CVE-2012-6718 on NVD →
Sharebar [sharebar] < 1.2.2 (closed)
unknown
[en] The sharebar plugin before 1.2.2 for WordPress has SQL injection.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- Aug 28, 2019
CVE-2012-6719 on NVD →
Sharebar [sharebar] < 1.2.6 (closed)
unknown
This plugin is prone to sharebar-admin.php page parameter cross site scripting vulnerability
Update the plugin.
- Affected:
- up to 1.2.6
- Fixed in:
- 1.2.6
- Disclosed:
- May 15, 2015
Sharebar [sharebar] < 1.2.4 (closed)
unknown
This plugin is prone to wp-admin/options-general.php status parameter cross site scripting vulnerability.
Update the plugin.
- Affected:
- up to 1.2.4
- Fixed in:
- 1.2.4
- Disclosed:
- May 15, 2015
Sharebar <= 1.4.2 - Cross-Site Scripting
medium
Multiple cross-site request forgery (CSRF) vulnerabilities in the Sharebar plugin 1.4.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) modify buttons, or (3) insert cross-site scripting (XSS) sequences.
- CVSS:
- 6.1
- Affected:
- up to 1.4.2
- Fixed in:
- 1.4.3
- Disclosed:
- Sep 24, 2013
CVE-2013-3491 on NVD →
Sharebar [sharebar] < 1.4.3 (closed)
unknown
[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the Sharebar plugin 1.2.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) modify buttons, or (3) insert cross-site scripting (XSS) sequences.
- Affected:
- up to 1.4.3
- Fixed in:
- 1.4.3
- Disclosed:
- Jul 16, 2013
CVE-2013-3491 on NVD →
Sharebar <= 1.2.1 - SQL Injection
critical
The sharebar plugin before 1.2.2 for WordPress has SQL injection via id parameter.
- CVSS:
- 9.8
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- May 15, 2012
CVE-2012-6719 on NVD →
Sharebar <= 1.2.1 - Cross-Site Scripting
medium
The Sharebar plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute in a victim's browser.
- CVSS:
- 6.1
- Affected:
- up to 1.2.1
- Fixed in:
- 1.2.2
- Disclosed:
- May 15, 2012
CVE-2012-6718 on NVD →
Sharebar [sharebar] < 1.2.2 (closed)
unknown
Sharebar plugin is prone to multiple cross-site scripting and SQL-injection vulnerabilities because of failure to properly clean up user-supplied input. It allows an attacker to steal cookie-based authentication credentials, access or modify data, compromise the application or exploit latent vulnerabilities in the unde...
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
- Disclosed:
- May 15, 2012
Sharebar [sharebar] < 1.2.2 (closed)
unknown
The Sharebar WordPress plugin was affected by a SQL Injection & Cross Site Scripting security vulnerability.
- Affected:
- up to 1.2.2
- Fixed in:
- 1.2.2
Sharebar [sharebar] < 1.4.1 (closed)
unknown
sharebar-admin.php page Parameter XSS
- Affected:
- up to 1.4.1
- Fixed in:
- 1.4.1
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database