plugin

Shariff Sharing Vulnerabilities

4 known security issues reported for the Shariff Sharing WordPress plugin. Most recent disclosed Dec 5, 2014.

1 high

Running Shariff Sharing on your site? Check whether your installed version is affected.

Scan your site free

Shariff Sharing < 1.0.8 - Stored Cross-Site Scripting

high

The Shariff Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shariff_image' parameter in versions before 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...

CVSS:
7.2
Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Dec 5, 2014

Shariff for WordPress [shariff-sharing] < 1.0.8

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update the plugin.

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Dec 5, 2014

Shariff for WordPress [shariff-sharing] < 1.0.8

unknown

The Shariff Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘shariff_image' parameter in versions before 1.0.8 due to insufficient input sanitization and output escaping. This makes it possible for attackers to inject arbitrary web scripts in pages that will execute whenever a user acc...

Affected:
up to 1.0.8
Fixed in:
1.0.8
Disclosed:
Dec 5, 2014

Shariff for WordPress [shariff-sharing] < 1.0.8

unknown

On the &quot;Settings &gt; Shariff&quot; screen, the input field &#039;shariff_image&#039; is saved without any validation. Malicious JavaScript can be injected. Screenshots: http://imgur.com/hipNRLW http://imgur.com/N6djVaE

Affected:
up to 1.0.8
Fixed in:
1.0.8

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database