plugin

Simple Share Buttons Adder Vulnerabilities

14 known security issues reported for the Simple Share Buttons Adder WordPress plugin. Most recent disclosed Jun 18, 2024.

2 high 4 medium

Running Simple Share Buttons Adder on your site? Check whether your installed version is affected.

Scan your site free

Simple Share Buttons Adder [simple-share-buttons-adder] < 3.5.1

unknown

[en] The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed

Affected:
up to 3.5.1
Fixed in:
3.5.1
Disclosed:
Jun 18, 2024

CVE-2024-4094 on NVD →

Simple Share Buttons Adder <= 8.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

medium

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...

CVSS:
4.4
Affected:
up to 3.5.0
Fixed in:
3.5.1
Disclosed:
May 28, 2024

CVE-2024-4094 on NVD →

Simple Share Buttons Adder [simple-share-buttons-adder] < 8.4.12

unknown

[en] The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...

Affected:
up to 8.4.12
Fixed in:
8.4.12
Disclosed:
Feb 20, 2024

CVE-2024-0621 on NVD →

Simple Share Buttons Adder <= 8.4.11 - Authenticated(Administrator+) Stored Cross-Site Scripting via CSS Settings

medium

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...

CVSS:
4.4
Affected:
up to 8.4.11
Fixed in:
8.4.12
Disclosed:
Feb 14, 2024

CVE-2024-0621 on NVD →

Simple Share Buttons Adder [simple-share-buttons-adder] < 8.4.7

unknown

[en] Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions.

Affected:
up to 8.4.7
Fixed in:
8.4.7
Disclosed:
May 25, 2023

CVE-2022-47178 on NVD →

Simple Share Buttons Adder <= 8.4.6 - Cross-Site Request Forgery

medium

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted...

CVSS:
4.3
Affected:
up to 8.4.6
Fixed in:
8.4.7
Disclosed:
Apr 19, 2023

CVE-2022-47178 on NVD →

Simple Share Buttons Adder [simple-share-buttons-adder] < 6.0.1

unknown

[en] The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Aug 12, 2019

CVE-2015-9303 on NVD →

Simple Share Buttons Adder [simple-share-buttons-adder] < 6.0.1

unknown

Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code. Update plugin.

Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Dec 20, 2015

Simple Share Buttons Adder <= 6.0.0 - Reflected Cross-Site Scripting

medium

The simple-share-buttons-adder plugin before 6.0.1 for WordPress has XSS via 'url' parameter in ssba_buttons.php file.

CVSS:
6.1
Affected:
up to 6.0.1
Fixed in:
6.0.1
Disclosed:
Jun 2, 2015

CVE-2015-9303 on NVD →

Simple Share Buttons Adder [simple-share-buttons-adder] < 4.5

unknown

[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to w...

Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Jul 3, 2014

CVE-2014-4717 on NVD →

Simple Share Buttons Adder <= 4.4 - Cross-Site Request Forgery

high

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4. This is due to missing nonce validation on simple-share-buttons-adder page. This makes it possible for unauthenticated attackers to inject malicious web scripts via the 'ssba_share_text...

CVSS:
8.8
Affected:
up to 4.4
Fixed in:
4.5
Disclosed:
Jun 26, 2014

CVE-2014-4717 on NVD →

Simple Share Buttons Adder <= 4.4 - Cross-Site Request Forgery

high

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to execute arbitrary javascript in the context of the Homepage, Pages, Posts,...

CVSS:
8.1
Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Jun 26, 2014

Simple Share Buttons Adder [simple-share-buttons-adder] < 4.5

unknown

The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to execute arbitrary javascript in the context of the Homepage, Pages, Posts,...

Affected:
up to 4.5
Fixed in:
4.5
Disclosed:
Jun 26, 2014

Simple Share Buttons Adder [simple-share-buttons-adder] < 4.5

unknown

The Simple Share Buttons Adder WordPress plugin was affected by an options-general.php ssba_share_text Parameter Stored XSS Weakness security vulnerability.

Affected:
up to 4.5
Fixed in:
4.5

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database