Show filters
522 Total Results
Displaying 341-350 of 522
Sort by:
Attacker Value
Unknown
CVE-2021-39321
Disclosure Date: October 21, 2021 (last updated February 23, 2025)
Version 3.3.23 of the Sassy Social Share WordPress plugin is vulnerable to PHP Object Injection via the wp_ajax_heateor_sss_import_config AJAX action due to deserialization of unvalidated user supplied inputs via the import_config function found in the ~/admin/class-sassy-social-share-admin.php file. This can be exploited by underprivileged authenticated users due to a missing capability check on the import_config function.
0
Attacker Value
Unknown
CVE-2021-24656
Disclosure Date: October 11, 2021 (last updated February 23, 2025)
The Simple Social Media Share Buttons WordPress plugin before 3.2.4 does not escape the Share Title settings before outputting it in the frontend pages or posts (depending on the settings used), allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
0
Attacker Value
Unknown
CVE-2021-24508
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
The Smash Balloon Social Post Feed WordPress plugin before 2.19.2 does not sanitise or escape the feedID POST parameter in its feed_locator AJAX action (available to both authenticated and unauthenticated users) before outputting a truncated version of it in the admin dashboard, leading to an unauthenticated Stored Cross-Site Scripting issue which will be executed in the context of a logged in administrator.
0
Attacker Value
Unknown
CVE-2021-39322
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
The Easy Social Icons plugin <= 3.0.8 for WordPress echoes out the raw value of `$_SERVER['PHP_SELF']` in its main file. On certain configurations including Apache+modPHP this makes it possible to use it to perform a reflected Cross-Site Scripting attack by injecting malicious code in the request path.
0
Attacker Value
Unknown
CVE-2021-24486
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The Simple Social Media Share Buttons – Social Sharing for Everyone WordPress plugin before 3.2.3 did not escape the align and like_button_size parameters of its SSB shortcode, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2021-24411
Disclosure Date: August 16, 2021 (last updated February 23, 2025)
The Social Tape WordPress plugin through 1.0 does not have CSRF checks in place when saving its settings, and do not sanitise or escape them before outputting them back in the page, leading to a stored Cross-Site Scripting issue via a CSRF attack
0
Attacker Value
Unknown
CVE-2021-24196
Disclosure Date: April 05, 2021 (last updated February 22, 2025)
The Social Slider Widget WordPress plugin before 1.8.5 allowed Authenticated Reflected XSS in the plugin settings page as the ‘token_error’ parameter can be controlled by users and it is directly echoed without being sanitized
0
Attacker Value
Unknown
CVE-2021-24143
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Unvalidated input in the AccessPress Social Icons plugin, versions before 1.8.1, did not sanitise its widget attribute, allowing accounts with post permission, such as author, to perform SQL injections.
0
Attacker Value
Unknown
CVE-2021-24137
Disclosure Date: March 18, 2021 (last updated February 22, 2025)
Unvalidated input in the Blog2Social WordPress plugin, versions before 6.3.1, lead to SQL Injection in the Re-Share Posts feature, allowing authenticated users to inject arbitrary SQL commands.
0
Attacker Value
Unknown
CVE-2020-4942
Disclosure Date: December 31, 2020 (last updated February 22, 2025)
IBM Curam Social Program Management 7.0.9 and 7.0.11 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 191942.
0