Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-64673
HistoryJun 09, 2022 - 12:00 a.m.

WordPress Social Share Buttons plugin cross-site request forgery vulnerability

2022-06-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
16
wordpress
social share buttons
cross-site request forgery
vulnerability
token authentication
php language
attack

EPSS

0.001

Percentile

20.9%

WordPress and WordPress plugin are both products of the WordPress Foundation. WordPress is a blogging platform developed using the PHP language. WordPress plugin is an application plugin. WordPress Social Share Buttons plugin 2.2.2 and earlier versions are vulnerable to cross-site request forgery due to a lack of token authentication for cross-site request forgery. An attacker could use this vulnerability to spoof malicious requests to trick victims into clicking through to perform sensitive actions.

EPSS

0.001

Percentile

20.9%

Related for CNVD-2022-64673