Deserialization of Untrusted Data Vulnerability Affects Social Media Share Buttons
CVE-2024-2721

8.2HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
20 March 2024

Summary

A deserialization vulnerability exists in the Sygnoos Social Media Share Buttons plugin, which can be exploited to process untrusted data improperly. This can lead to various security risks, including arbitrary code execution. The affected versions range from n/a to 2.1.0, posing a significant risk to websites utilizing this plugin. Administrators are encouraged to review and update their installations to safeguard against potential exploitation.

Affected Version(s)

Social Media Share Buttons <= 2.1.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.