plugin

Social Sharing Toolkit Vulnerabilities

6 known security issues reported for the Social Sharing Toolkit WordPress plugin. Most recent disclosed Jan 30, 2023.

1 high 2 medium

Running Social Sharing Toolkit on your site? Check whether your installed version is affected.

Scan your site free

Social Sharing Toolkit [social-sharing-toolkit] <= 2.6 (unfixed + closed)

unknown

[en] The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users su...

Affected:
up to 2.6
Fix:
No patched version reported
Disclosed:
Jan 30, 2023

CVE-2022-4835 on NVD →

Social Sharing Toolkit <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

medium

The Social Sharing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'title'. This makes it possible for authenticated attackers with contr...

CVSS:
6.4
Affected:
up to 2.6
Fix:
No patched version reported
Disclosed:
Jan 4, 2023

CVE-2022-4835 on NVD →

Social Sharing Toolkit [social-sharing-toolkit] < 2.1.2 (closed)

unknown

[en] Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Nov 1, 2013

CVE-2013-2701 on NVD →

Social Sharing Toolkit [social-sharing-toolkit] < 2.1.2 (closed)

unknown

[en] Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
Oct 25, 2013

CVE-2013-6280 on NVD →

Social Sharing Toolkit <= 2.1.1 - Cross-Site Request Forgery

high

Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.

CVSS:
8.8
Affected:
up to 2.1.1
Fixed in:
2.1.2
Disclosed:
Oct 17, 2013

CVE-2013-2701 on NVD →

Social Sharing Toolkit < 2.1.2 - Cross-Site Scripting

medium

Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS:
6.1
Affected:
up to 2.1.2
Fixed in:
2.1.2
Disclosed:
May 22, 2013

CVE-2013-6280 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database