What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in SuPlugins Superb Social Media Share Buttons and Follow Buttons for WordPress plugin <= 1.1.3 versions.
Explanation of Vulnerability in Simple Terms
The Superb Social Media Share Buttons and Follow Buttons plugin for WordPress versions up to 1.1.3 lacks proper CSRF protection on administrative actions. An attacker can craft a malicious webpage that, when visited by a logged-in site administrator, performs unwanted changes to plugin settings without the admin's knowledge or consent.
What an attacker can do
Modify plugin settings or perform administrative actions on the site without the admin's consent.
Potential impact on your site
Plugin settings could be altered by attackers, potentially affecting social media sharing functionality or site configuration.
Conditions required to exploit
A logged-in WordPress administrator must visit a malicious webpage controlled by the attacker.
Key dates
External resources
Related vulnerabilities