CVE-2018-11632: CSRF
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php CSRF. There's no nonce or capability check in the whatsappsharesettingaddupdate() function.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11632?
CVE-2018-11632 is a vulnerability found in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin for WordPress.
How does CVE-2018-11632 affect the plugin?
CVE-2018-11632 allows an attacker to change the plugin settings if an admin user visits a crafted URL created by the attacker.
What is the severity of CVE-2018-11632?
CVE-2018-11632 has a severity score of 6.5.
How can I fix CVE-2018-11632?
To fix CVE-2018-11632, update the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin to version 1.0.9 or higher.
Where can I find more information about CVE-2018-11632?
You can find more information about CVE-2018-11632 at the following references: [Reference1](http://labs.threatpress.com/cross-site-request-forgery-csrf-in-add-social-share-messenger-buttons-whatsapp-and-viber-plugin/) and [Reference2](https://wordpress.org/plugins/add-social-share-buttons/#developers).