The Social Warfare plugin for WordPress, called the Social Sharing Plugin, has a security issue. This issue, also known as Cross-Site Request Forgery, affects all versions of the plugin up to 4.4.5.1. The problem lies in the options_page_scan_url() function, where the plugin does not properly check for a specific code called a “nonce”. This means that anyone who is not logged in can trick a website owner into clicking on a link that can cause a scan to occur.