CVE-2014-4717

Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to wp-admin/options-general.php, which is not properly handled in the homepage, and unspecified vectors related to (2) Pages, (3) Posts, (4) Category/Archive pages or (5) post Excerpts.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
VendorProductVersion
sharethissimple_share_buttons_adder
𝑥
≤ 4.4
sharethissimple_share_buttons_adder
1.0
sharethissimple_share_buttons_adder
1.1
sharethissimple_share_buttons_adder
1.2
sharethissimple_share_buttons_adder
1.3
sharethissimple_share_buttons_adder
1.4
sharethissimple_share_buttons_adder
1.5
sharethissimple_share_buttons_adder
1.6
sharethissimple_share_buttons_adder
1.7
sharethissimple_share_buttons_adder
1.8
sharethissimple_share_buttons_adder
1.9
sharethissimple_share_buttons_adder
2.0
sharethissimple_share_buttons_adder
2.1
sharethissimple_share_buttons_adder
2.2
sharethissimple_share_buttons_adder
2.3
sharethissimple_share_buttons_adder
2.4
sharethissimple_share_buttons_adder
2.5
sharethissimple_share_buttons_adder
2.6
sharethissimple_share_buttons_adder
2.7
sharethissimple_share_buttons_adder
2.8
sharethissimple_share_buttons_adder
2.9
sharethissimple_share_buttons_adder
3.0
sharethissimple_share_buttons_adder
3.1
sharethissimple_share_buttons_adder
3.2
sharethissimple_share_buttons_adder
3.3
sharethissimple_share_buttons_adder
3.4
sharethissimple_share_buttons_adder
3.5
sharethissimple_share_buttons_adder
3.6
sharethissimple_share_buttons_adder
3.7
sharethissimple_share_buttons_adder
3.8
sharethissimple_share_buttons_adder
3.9
sharethissimple_share_buttons_adder
4.0
sharethissimple_share_buttons_adder
4.1
sharethissimple_share_buttons_adder
4.2
sharethissimple_share_buttons_adder
4.3
𝑥
= Vulnerable software versions