CVE-2022-33960: WordPress Social Share Buttons by Supsystic plugin <= 2.2.3 - Multiple Authenticated SQL Injection (SQLi) vulnerabilities
Multiple Authenticated (subscriber or higher user role) SQL Injection (SQLi) vulnerabilities in Social Share Buttons by Supsystic plugin <= 2.2.3 at WordPress.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-33960?
CVE-2022-33960 is a vulnerability in the Social Share Buttons by Supsystic plugin <= 2.2.3 for WordPress, which allows authenticated users with subscriber or higher user roles to execute SQL injection attacks.
How does CVE-2022-33960 affect the Social Share Buttons plugin?
CVE-2022-33960 allows authenticated users with subscriber or higher user roles to exploit SQL injection vulnerabilities in the Social Share Buttons plugin by Supsystic.
What is the severity of CVE-2022-33960?
The severity of CVE-2022-33960 is rated as high, with a CVSS score of 8.8.
How can I fix CVE-2022-33960?
To fix CVE-2022-33960, you should update the Social Share Buttons plugin to version 2.2.4 or higher.
Where can I find more information about CVE-2022-33960?
You can find more information about CVE-2022-33960 at the following references: [Patchstack](https://patchstack.com/database/vulnerability/social-share-buttons-by-supsystic/wordpress-social-share-buttons-by-supsystic-plugin-2-2-3-multiple-authenticated-sql-injection-sqli-vulnerabilities) and [WordPress.org](https://wordpress.org/plugins/social-share-buttons-by-supsystic/#developers)