WordPress Community Forum

WordPress Support => WordPress Vulnerability => Topic started by: Kailash on Jun 16, 2022, 06:22 AM

Title: WordPress Social Media Share Buttons plugin <= 3.8.1 - XSS Vulnerability
Post by: Kailash on Jun 16, 2022, 06:22 AM
WordPress Social Media Share Buttons | MashShare plugin <= 3.8.1 - Authenticated Stored Cross-Site Scripting (XSS) vulnerability

Plugin name: Social Media Share Buttons | MashShare
Vulnerable versions: <= 3.8.1
Fixed in: N/A
CVE ID: CVE-2021-36849
Classification: Cross Site Scripting (XSS)
Publicly disclosed: 2022-06-16

Vulnerability Details

Authenticated Stored Cross-Site Scripting (XSS) vulnerability discovered by Asif Nawaz Minhas (Patchstack Alliance) in WordPress Social Media Share Buttons plugin (versions <= 3.8.1).

Solution

No patched version available hence it is recommended to disable and delete this plugin until an update is available to address this.

Plugin Link: https://wordpress.org/plugins/mashsharer/