Extension WordPress
Vulnérabilités Social Sharing Plugin – Social Warfare
Cette page rassemble les failles publiées pour Social Sharing Plugin – Social Warfare, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Social Sharing Plugin – Social Warfare
9 fiches
Social Sharing Plugin – Social Warfare <= 4.5.5 – Authenticated (Contributor+) Stored Cross-Site Scripting
The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 4.5.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
*-4.5.5
4.5.6
19/02/2025
Several WordPress.org Plugins <= Various Versions – Injected Backdoor
Several plugins for WordPress hosted on WordPress.org have been compromised and injected with malicious PHP scripts. A malicious threat actor compromised the source code of various plugins and injected code that exfiltrates database credentials and is used to…
4.4.6.4-4.4.7.1
4.4.7.3
24/06/2024
Social Sharing Plugin – Social Warfare <= 4.4.5.1 – Cross-Site Request Forgery
The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.5.1. This is due to missing or incorrect nonce validation on the options_page_scan_url() function. This…
*-4.4.5.1
4.4.6
09/05/2024
Social Sharing Plugin – Social Warfare <= 4.4.6.1 – Authenticated(Contributor+) Stored Cross-Site Scripting via Shortcode
The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialWarfare' shortcode in all versions up to, and including, 4.4.6.1 due to insufficient input sanitization and output escaping on…
*-4.4.6.1
4.4.6.2
22/04/2024
Social Sharing Plugin – Social Warfare <= 4.4.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Social Sharing Plugin – Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes.…
*-4.4.3
4.4.4
06/11/2023
Social Warfare <= 4.3.1 – Cross-Site Request Forgery
The Social Warfare plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 4.3.1. This is due to missing or incorrect nonce validation on several AJAX actions. This makes it possible for unauthenticated…
*-4.3.1
4.4.0
05/01/2023
Social Warfare <= 4.3.0 – Missing Authorization
The Social Warfare plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on several AJAX actions in versions up to, and including, 4.3.0. This makes it possible for authenticated attackers, with subscriber-level permissions…
*-4.3.0
4.3.1
05/01/2023
Social Warfare <= 3.5.2 – Remote Code Execution
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.
[*, 3.5.3)
3.5.3
29/04/2021
Social Warfare <= 3.5.2 – Unauthenticated Arbitrary Settings Update
The Social Warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.
[*, 3.5.3)
3.5.3
21/03/2019
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.