What the vulnerability does
01Description
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
What the vulnerability does
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
Explanation of Vulnerability in Simple Terms
The Social Share Buttons by Supsystic WordPress plugin through version 2.2.3 contains a SQL injection vulnerability in its database queries. An authenticated attacker with low privileges can inject malicious SQL code to read or modify database contents, potentially exposing sensitive site data or user information. The vulnerability affects the plugin's core functionality and requires only network access and valid user credentials.
What an attacker can do
Read or modify the WordPress database by injecting SQL commands through the plugin.
Potential impact on your site
Attackers with user accounts can steal sensitive data, modify posts/pages, or compromise user information stored in your database.
Conditions required to exploit
Attacker must have a valid WordPress user account with low-level privileges (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities