Lucene search

K
cveWordfenceCVE-2023-5602
HistoryOct 20, 2023 - 8:15 a.m.

CVE-2023-5602

2023-10-2008:15:13
CWE-352
Wordfence
web.nvd.nist.gov
32
wordpress
plugin
vulnerability
cross-site request forgery
csrf
nvd
security advisory

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

26.3%

The Social Media Share Buttons & Social Sharing Icons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missing or incorrect nonce validation on several functions corresponding to AJAX actions. This makes it possible for unauthenticated attackers to invoke those actions via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Affected configurations

Nvd
Vulners
Node
ultimatelysocialsocial_media_share_buttons_\&_social_sharing_iconsRange2.8.5wordpress
VendorProductVersionCPE
ultimatelysocialsocial_media_share_buttons_\&_social_sharing_icons*cpe:2.3:a:ultimatelysocial:social_media_share_buttons_\&_social_sharing_icons:*:*:*:*:*:wordpress:*:*

CNA Affected

[
  {
    "vendor": "socialdude",
    "product": "Social Media Share Buttons & Social Sharing Icons",
    "versions": [
      {
        "version": "*",
        "status": "affected",
        "lessThanOrEqual": "2.8.5",
        "versionType": "semver"
      }
    ],
    "defaultStatus": "unaffected"
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.3

Confidence

High

EPSS

0.001

Percentile

26.3%