Extension WordPress
Vulnérabilités Social Rocket – Social Sharing Plugin
Cette page rassemble les failles publiées pour Social Rocket – Social Sharing Plugin, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Social Rocket – Social Sharing Plugin
7 fiches
Social Rocket – Social Sharing Plugin <= 1.3.4.2 – Authenticated (Subscriber+) Stored Cross-Site Scripting via id
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.3.4.2 due to insufficient input sanitization and output escaping. This makes…
*-1.3.4.2
1.3.5
22/04/2026
Social Rocket – Social Sharing Plugin <= 1.3.4 – Missing Authorization to Settings Update
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() and tweet_settings_update() functions in all versions up to, and including, 1.3.4. This…
*-1.3.4
1.3.4.1
06/01/2025
Social Rocket <= 1.3.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in all versions up to, and including, 1.3.4 due to insufficient input sanitization and output escaping on…
*-1.3.4
1.3.4.1
06/01/2025
Social Rocket <= 1.3.3 – Reflected Cross-Site Scripting
The Social Rocket plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-1.3.3
1.3.4
27/06/2024
Social Rocket <= 1.3.2 – Authenticated (Administrator+) Stored Cross-Site Scripting
The Social Rocket plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of its settings parameters in versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping. This makes it possible for…
*-1.3.2
1.3.3
19/09/2022
Social Rocket – Social Sharing Plugin < 1.2.10 – Cross-Site Request Forgery
Cross-site request forgery (CSRF) vulnerability in Social Sharing Plugin versions prior to 1.2.10 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
[*, 1.2.10)
1.2.10
22/07/2020
Social Rocket <= 1.2.9 – Cross-Site Request Forgery
The Social Rocket plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.9. This is due to missing or incorrect nonce validation on the admin_settings_post_actions() function. This makes it possible for unauthenticated…
*-1.2.9
1.2.10
22/07/2020
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.