plugin

Social Share Buttons By Supsystic Vulnerabilities

6 known security issues reported for the Social Share Buttons By Supsystic WordPress plugin. Most recent disclosed Jan 17, 2024.

1 critical 2 high 3 medium

Running Social Share Buttons By Supsystic on your site? Check whether your installed version is affected.

Scan your site free

Slider by Supsystic <= 1.8.6 - Missing Authorization

medium

The Slider by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.

CVSS:
4.3
Affected:
up to 2.2.9
Fix:
No patched version reported
Disclosed:
Jan 17, 2024

CVE-2024-47330 on NVD →

Social Share Buttons by Supsystic <= 2.2.6 - SQL Injection

critical

The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via the ‘value’ parameter in versions up to, and including, 2.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to ap...

CVSS:
9.8
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jul 6, 2022

Social Share Buttons by Supsystic <= 2.2.3 - Authenticated (Subscriber+) SQL Injection

high

The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via several unknown parameters in versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti...

CVSS:
8.8
Affected:
up to 2.2.6
Fixed in:
2.2.7
Disclosed:
Jun 9, 2022

CVE-2022-33960 on NVD →

Social Share Buttons by Supsystic <= 2.2.3 - Missing Authorization

medium

The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers with subscriber level permissions and above to perform a wide variety of act...

CVSS:
6.3
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Jun 9, 2022

CVE-2022-27235 on NVD →

Social Share Buttons by Supsystic <= 2.2.3 - Cross-Site Request Forgery to Settings Update

high

The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.

CVSS:
8.8
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
Jun 1, 2022

CVE-2022-1653 on NVD →

Social Share Buttons by Supsystic <= 2.2.3 - Cross-Site Request Forgery

medium

Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.

CVSS:
4.3
Affected:
up to 2.2.3
Fixed in:
2.2.4
Disclosed:
May 27, 2022

CVE-2021-36890 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database