← WordPress Vulnerabilities
WordPress security by component

Social Share Buttons By Supsystic

Social Share Buttons By Supsystic adds configurable social sharing buttons to WordPress content and pages.

Social Share Buttons By Supsystic (social-share-buttons-by-supsystic) is a WordPress plugin with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 22, 2022; the highest published CVSS base score is 8.5.

Plugin slug: social-share-buttons-by-supsystic

CVE-2022-33960: Social Share Buttons By Supsystic: SQL injection

Social Share Buttons By Supsystic is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.

PublishedJul 22, 2022
Safe version guidanceSee mitigation notes
Published vulnerabilities for social-share-buttons-by-supsystic
Safe version
Jul 22, 2022 CVE-2022-33960
Social Share Buttons By Supsystic: SQL injection
Social Share Buttons By Supsystic is affected by SQL injection. Exposure depends on how the affected operation is made reachable by the site. A successful request can alter database queries and expose or modify WordPress data.
See mitigation notes
CVE8.5
NVD8.8
Jul 22, 2022 CVE-2022-27235
Social Share Buttons By Supsystic: Broken access control
Social Share Buttons By Supsystic is affected by broken access control. Exposure depends on how the affected operation is made reachable by the site. A successful request can reach data or an operation that should be restricted to another user or a more privileged role.
See mitigation notes
CVE6.3
NVD8.8
Jun 02, 2022 CVE-2021-36890
Social Share Buttons By Supsystic: Cross-site request forgery
Social Share Buttons By Supsystic is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVD4.3