CVE-2023-5602: Social Media Share Buttons & Social Sharing Icons <= 2.8.5 - Cross-Site Request Forgery
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated attackers to invoke those actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-5602.
What is the severity of CVE-2023-5602?
CVE-2023-5602 has a severity score of 8.8 (High).
Which plugin for WordPress is affected by CVE-2023-5602?
The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is affected by CVE-2023-5602.
What is the cause of the vulnerability in CVE-2023-5602?
The vulnerability in CVE-2023-5602 is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions in the Social Media Share Buttons & Social Sharing Icons plugin for WordPress.
Are all versions of the plugin affected by CVE-2023-5602?
Yes, all versions up to and including 2.8.5 of the Social Media Share Buttons & Social Sharing Icons plugin for WordPress are affected by CVE-2023-5602.