Slider by Supsystic <= 1.8.6 - Missing Authorization
medium
The Slider by Supsystic plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 2.2.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 17, 2024
CVE-2024-47330 on NVD →
Social Share Buttons by Supsystic <= 2.2.6 - SQL Injection
critical
The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via the ‘value’ parameter in versions up to, and including, 2.2.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for attackers to ap...
- CVSS:
- 9.8
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.7
- Disclosed:
- Jul 6, 2022
Social Share Buttons by Supsystic <= 2.2.3 - Authenticated (Subscriber+) SQL Injection
high
The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to SQL Injection via several unknown parameters in versions up to, and including, 2.2.3 due to insufficient escaping on the user supplied parameters and lack of sufficient preparation on the existing SQL query. This makes it possible for authenti...
- CVSS:
- 8.8
- Affected:
- up to 2.2.6
- Fixed in:
- 2.2.7
- Disclosed:
- Jun 9, 2022
CVE-2022-33960 on NVD →
Social Share Buttons by Supsystic <= 2.2.3 - Missing Authorization
medium
The Social Share Buttons by Supsystic plugin for WordPress is vulnerable to authorization bypass due to missing capability checks on various functions in versions up to, and including, 2.2.3. This makes it possible for authenticated attackers with subscriber level permissions and above to perform a wide variety of act...
- CVSS:
- 6.3
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.4
- Disclosed:
- Jun 9, 2022
CVE-2022-27235 on NVD →
Social Share Buttons by Supsystic <= 2.2.3 - Cross-Site Request Forgery to Settings Update
high
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.
- CVSS:
- 8.8
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.4
- Disclosed:
- Jun 1, 2022
CVE-2022-1653 on NVD →
Social Share Buttons by Supsystic <= 2.2.3 - Cross-Site Request Forgery
medium
Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
- CVSS:
- 4.3
- Affected:
- up to 2.2.3
- Fixed in:
- 2.2.4
- Disclosed:
- May 27, 2022
CVE-2021-36890 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database