Simple Share Buttons Adder [simple-share-buttons-adder] < 3.5.1
unknown
[en] The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
- Affected:
- up to 3.5.1
- Fixed in:
- 3.5.1
- Disclosed:
- Jun 18, 2024
CVE-2024-4094 on NVD →
Simple Share Buttons Adder <= 8.5.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.5.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...
- CVSS:
- 4.4
- Affected:
- up to 3.5.0
- Fixed in:
- 3.5.1
- Disclosed:
- May 28, 2024
CVE-2024-4094 on NVD →
Simple Share Buttons Adder [simple-share-buttons-adder] < 8.4.12
unknown
[en] The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and a...
- Affected:
- up to 8.4.12
- Fixed in:
- 8.4.12
- Disclosed:
- Feb 20, 2024
CVE-2024-0621 on NVD →
Simple Share Buttons Adder <= 8.4.11 - Authenticated(Administrator+) Stored Cross-Site Scripting via CSS Settings
medium
The Simple Share Buttons Adder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.4.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,...
- CVSS:
- 4.4
- Affected:
- up to 8.4.11
- Fixed in:
- 8.4.12
- Disclosed:
- Feb 14, 2024
CVE-2024-0621 on NVD →
Simple Share Buttons Adder [simple-share-buttons-adder] < 8.4.7
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in Simple Share Buttons Simple Share Buttons Adder plugin <= 8.4.7 versions.
- Affected:
- up to 8.4.7
- Fixed in:
- 8.4.7
- Disclosed:
- May 25, 2023
CVE-2022-47178 on NVD →
Simple Share Buttons Adder <= 8.4.6 - Cross-Site Request Forgery
medium
The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.6. This is due to missing or incorrect nonce validation on one of its functions. This makes it possible for unauthenticated attackers to invoke this function via a forged request granted...
- CVSS:
- 4.3
- Affected:
- up to 8.4.6
- Fixed in:
- 8.4.7
- Disclosed:
- Apr 19, 2023
CVE-2022-47178 on NVD →
Simple Share Buttons Adder [simple-share-buttons-adder] < 6.0.1
unknown
[en] The simple-share-buttons-adder plugin before 6.0.0 for WordPress has XSS.
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
- Disclosed:
- Aug 12, 2019
CVE-2015-9303 on NVD →
Simple Share Buttons Adder [simple-share-buttons-adder] < 6.0.1
unknown
Because of this vulnerability, the attackers can inject arbitrary JavaScript or HTML code.
Update plugin.
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
- Disclosed:
- Dec 20, 2015
Simple Share Buttons Adder <= 6.0.0 - Reflected Cross-Site Scripting
medium
The simple-share-buttons-adder plugin before 6.0.1 for WordPress has XSS via 'url' parameter in ssba_buttons.php file.
- CVSS:
- 6.1
- Affected:
- up to 6.0.1
- Fixed in:
- 6.0.1
- Disclosed:
- Jun 2, 2015
CVE-2015-9303 on NVD →
Simple Share Buttons Adder [simple-share-buttons-adder] < 4.5
unknown
[en] Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to w...
- Affected:
- up to 4.5
- Fixed in:
- 4.5
- Disclosed:
- Jul 3, 2014
CVE-2014-4717 on NVD →
Simple Share Buttons Adder <= 4.4 - Cross-Site Request Forgery
high
The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4. This is due to missing nonce validation on simple-share-buttons-adder page. This makes it possible for unauthenticated attackers to inject malicious web scripts via the 'ssba_share_text...
- CVSS:
- 8.8
- Affected:
- up to 4.4
- Fixed in:
- 4.5
- Disclosed:
- Jun 26, 2014
CVE-2014-4717 on NVD →
Simple Share Buttons Adder <= 4.4 - Cross-Site Request Forgery
high
The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to execute arbitrary javascript in the context of the Homepage, Pages, Posts,...
- CVSS:
- 8.1
- Affected:
- up to 4.5
- Fixed in:
- 4.5
- Disclosed:
- Jun 26, 2014
Simple Share Buttons Adder [simple-share-buttons-adder] < 4.5
unknown
The Simple Share Buttons Adder plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticated attackers to execute arbitrary javascript in the context of the Homepage, Pages, Posts,...
- Affected:
- up to 4.5
- Fixed in:
- 4.5
- Disclosed:
- Jun 26, 2014
Simple Share Buttons Adder [simple-share-buttons-adder] < 4.5
unknown
The Simple Share Buttons Adder WordPress plugin was affected by an options-general.php ssba_share_text Parameter Stored XSS Weakness security vulnerability.
- Affected:
- up to 4.5
- Fixed in:
- 4.5
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database