The Simple Share Buttons Adder WordPress plugin before 8.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
References
Link | Resource |
---|---|
https://wpscan.com/vulnerability/04b2feba-e009-4fce-8539-5dfdb4300433/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2024-06-18 06:15
Updated : 2024-07-05 13:41
NVD link : CVE-2024-4094
Mitre link : CVE-2024-4094
CVE.ORG link : CVE-2024-4094
JSON object : View
Products Affected
sharethis
- simple_share_buttons_adder
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')