WordPress Superb Social Media Share Buttons and Follow Buttons Plugin <= 1.1.3 is vulnerable to Broken Access Control
CVE-2023-29428
8.8HIGH
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 10 November 2023
Summary
A Cross-Site Request Forgery (CSRF) vulnerability exists in the SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin. This security flaw affects versions up to 1.1.3 and can be exploited to perform unauthorized actions on behalf of users without their consent. It poses a risk to website integrity, potentially allowing attackers to manipulate user actions if they can trick the user into clicking a malicious link while logged into WordPress.
Affected Version(s)
Superb Social Media Share Buttons and Follow Buttons for WordPress <= 1.1.3
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Abdi Pranata (Patchstack Alliance)