← Back

CVE-2014-4717

nvd nist
Published: Jul 3, 2014Modified: May 6, 2026

JSON object

Loading...
6.8
Vector
AV:N/AC:M/Au:N/C:P/I:P/A:P
Exploitability: 8.6 / Impact: 6.4
Source: NVD

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to wp-admin/options-general.php, which is not properly handled in the homepage, and unspecified vectors related to (2) Pages, (3) Posts, (4) Category/Archive pages or (5) post Excerpts.

Affected (35)

1 product
Simple Share Buttons Adder
Configuration A
35 vulnerable
Vulnerable SoftwareAffected Versions
Sharethis
Up to 4.4
Version 1.0
Version 1.1
Version 1.2
Version 1.3
Version 1.4
Version 1.5
Version 1.6
Version 1.7
Version 1.8
Version 1.9
Version 2.0
Version 2.1
Version 2.2
Version 2.3
Version 2.4
Version 2.5
Version 2.6
Version 2.7
Version 2.8
Version 2.9
Version 3.0
Version 3.1
Version 3.2
Version 3.3
Version 3.4
Version 3.5
Version 3.6
Version 3.7
Version 3.8
Version 3.9
Version 4.0
Version 4.1
Version 4.2
Version 4.3

Timeline

No history available yet.