CVE-2021-36890: WordPress Social Share Buttons by Supsystic plugin <= 2.2.2 - Cross-Site Request Forgery (CSRF) vulnerability
Published May 31, 2022
·Updated
Cross-Site Request Forgery (CSRF) vulnerability in Social Share Buttons by Supsystic plugin <= 2.2.2 at WordPress.
Affected Software
1 affected component
Supsystic Social Share Buttons Wordpress<=2.2.2
Remediation
Information
Deactivate and delete. No reply from the vendor. Plugin closed, closure is temporary, pending a full review.
Event History
May 31, 2022
CVE Published
via MITRE·07:30 PM
Data Sourced
via MITRE·07:30 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-36890?
The severity of CVE-2021-36890 is medium with a severity value of 4.3.
2
What is the affected software of CVE-2021-36890?
The affected software of CVE-2021-36890 is the Social Share Buttons by Supsystic plugin version 2.2.2 or lower for WordPress.
3
How does the CSRF vulnerability in CVE-2021-36890 work?
The CSRF vulnerability in CVE-2021-36890 allows attackers to trick authenticated users into performing unwanted actions without their consent.
4
Is there a patch available for CVE-2021-36890?
Yes, a patch is available for CVE-2021-36890. It is recommended to update to the latest version of the Social Share Buttons by Supsystic plugin.
5
How can I fix CVE-2021-36890?
To fix CVE-2021-36890, you should update the Social Share Buttons by Supsystic plugin to the latest version.