Input validation vulnerability in Simple Social Media Share Buttons – Social Sharing for Everyone 3.2.2

The Simple Social Media Share Buttons plugin before version 3.2.3 had a security flaw which allowed anyone with a Contributor or higher role to perform a type of attack called ‘Stored Cross-Site Scripting’. This attack could be done by not ‘escaping’ (protecting) the parameters of the plugin’s ‘shortcode’ (a type of code). This made it possible for malicious content to be stored and then run when the shortcode was used.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.