Input validation vulnerability in Really Simple Facebook Twitter Share Buttons 2.10.5

The Really Simple Facebook Twitter Share Buttons plugin for WordPress has a security vulnerability in versions before 2.10.5. This vulnerability means that attackers can make changes to the settings page without being logged in, as long as they can get an administrator to click on a malicious link. This is because the plugin is not properly validating nonces (special codes used to verify a request) when the really_simple_share_settings function is used.

Detected in:

Really Simple Facebook Twitter Share Buttons open vulnerable versions: >= * < 2.10.5

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.