3 results (0.014 seconds)

CVSS: 10.0EPSS: 0%CPEs: 1EXPL: 0

28 Aug 2023 — Cross-Site Request Forgery (CSRF) vulnerability in Sumo Social Share Boost plugin <= 4.5 versions. Vulnerabilidad de Cross-Site Request Forgery (CSRF) en el complemento Sumo Social Share Boost en versiones <= 4.5. The Social Share Boost plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.5. This is due to missing or incorrect nonce validation on the 'syntatical_settings_content' function. This makes it possible for unauthenticated attackers to change the p... • https://patchstack.com/database/vulnerability/social-share-boost/wordpress-social-share-boost-plugin-4-5-cross-site-request-forgery-csrf-vulnerability?_s_id=cve • CWE-352: Cross-Site Request Forgery (CSRF) •

CVSS: 5.9EPSS: 0%CPEs: 1EXPL: 0

07 Jul 2023 — Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Autenticada Almacenada (admin+) en el plugin Sumo Social Share Boost en la versión 4.4 o anteriores. The Social Share Boost plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administ... • https://patchstack.com/database/vulnerability/social-share-boost/wordpress-social-share-boost-plugin-4-4-cross-site-scripting-xss-vulnerability-2?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

19 Apr 2023 — Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Sumo Social Share Boost plugin <= 4.4 versions. Vulnerabilidad de Cross-Site Scripting (XSS) Autenticada Almacenada (admin+) en el plugin Sumo Social Share Boost en la versión 4.4 o anteriores. The Social Share Boost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ssboost shortcode in versions up to, and including, 4.4 due to insufficient input sanitization and output escaping. This makes it possible for authen... • https://patchstack.com/database/vulnerability/social-share-boost/wordpress-social-share-boost-plugin-4-4-cross-site-scripting-xss-vulnerability?_s_id=cve • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •