Social Sharing Toolkit [social-sharing-toolkit] <= 2.6 (unfixed + closed)
unknown
[en] The Social Sharing Toolkit WordPress plugin through 2.6 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users su...
- Affected:
- up to 2.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 30, 2023
CVE-2022-4835 on NVD →
Social Sharing Toolkit <= 2.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
medium
The Social Sharing Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes like 'title'. This makes it possible for authenticated attackers with contr...
- CVSS:
- 6.4
- Affected:
- up to 2.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 4, 2023
CVE-2022-4835 on NVD →
Social Sharing Toolkit [social-sharing-toolkit] < 2.1.2 (closed)
unknown
[en] Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Nov 1, 2013
CVE-2013-2701 on NVD →
Social Sharing Toolkit [social-sharing-toolkit] < 2.1.2 (closed)
unknown
[en] Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- Oct 25, 2013
CVE-2013-6280 on NVD →
Social Sharing Toolkit <= 2.1.1 - Cross-Site Request Forgery
high
Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.
- CVSS:
- 8.8
- Affected:
- up to 2.1.1
- Fixed in:
- 2.1.2
- Disclosed:
- Oct 17, 2013
CVE-2013-2701 on NVD →
Social Sharing Toolkit < 2.1.2 - Cross-Site Scripting
medium
Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
- CVSS:
- 6.1
- Affected:
- up to 2.1.2
- Fixed in:
- 2.1.2
- Disclosed:
- May 22, 2013
CVE-2013-6280 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database