Extension WordPress
Vulnérabilités Social Share, Social Login and Social Comments Plugin – Super Socializer
Cette page rassemble les failles publiées pour Social Share, Social Login and Social Comments Plugin – Super Socializer, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Social Share, Social Login and Social Comments Plugin – Super Socializer
12 fiches
Social Share, Social Login and Social Comments Plugin <= 7.14.5 – Reflected Cross-Site Scripting via 'heateor_mastodon_share' Parameter
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'heateor_mastodon_share' parameter in all versions up to, and including, 7.14.5 due to insufficient input sanitization…
*-7.14.5
Non indiqué
07/07/2026
Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.14 – Unauthenticated Limited SQL Injection via 'SuperSocializerKey'
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Limited SQL Injection via the ‘SuperSocializerKey’ parameter in all versions up to, and including, 7.14 due to insufficient escaping on…
*-7.14
7.14.1
20/01/2025
Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.68 – Authentication Bypass via Disqus OAuth provider
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 7.13.68. This is due to insufficient verification on the user being…
*-7.13.68
7.14
05/11/2024
Social Share, Social Login and Social Comments Plugin – Super Socializer <= 7.13.63 – Authenticated (Admin+) Stored Cross-Site Scripting
The Social Share, Social Login and Social Comments Plugin – Super Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 7.13.63 due to insufficient input sanitization and…
*-7.13.63
7.13.64
25/03/2024
Super Socializer <= 7.13.54 – Cross-Site Request Forgery
The Super Socializer plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce checks on several functions such as heateor_ss_twitcount_notification_read, heateor_ss_gdpr_notification_read, heateor_ss_fb_redirection_notification_read, heateor_ss_twitter_callback_notification_read, heateor_ss_linkedin_redirect_url_notification_read, heateor_ss_fb_count_notification_read, heateor_ss_twitter_new_callback_notification_read, and more in versions up to, and including, 7.13.54.…
*-7.13.54
7.13.55
05/09/2023
Super Socializer <= 7.13.54 – Missing Authorization
The Super Socializer plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on several functions such as heateor_ss_twitcount_notification_read, heateor_ss_gdpr_notification_read, heateor_ss_fb_redirection_notification_read, heateor_ss_twitter_callback_notification_read, heateor_ss_linkedin_redirect_url_notification_read, heateor_ss_fb_count_notification_read, heateor_ss_twitter_new_callback_notification_read, and more in versions up to, and including,…
*-7.13.54
7.13.55
05/09/2023
Super Socializer <= 7.13.53 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Super Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins [TheChamp-Counter] and [TheChamp-Sharing] shortcodes in versions up to, and including, 7.13.53 due to insufficient input sanitization and output escaping on the url user…
*-7.13.53
7.13.54
11/07/2023
Super Socializer <= 7.13.52 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Super Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in versions up to, and including, 7.13.52 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-7.13.52
7.13.53
19/06/2023
Social Share, Social Login and Social Comments <= 7.13.51 – Reflected Cross-Site Scripting
The Social Share, Social Login and Social Comments plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $targetUrls value in versions up to, and including, 7.13.51 due to insufficient input sanitization and output escaping. This makes…
[*, 7.13.52)
7.13.52
29/05/2023
Super Socializer <= 7.13.44 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
The Super Socializer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in versions up to, and including, 7.13.44 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…
*-7.13.44
7.13.45
23/12/2022
Social Share, Social Login and Social Comments < 7.13.30 – Reflected Cross-Site Scripting
The Social Share, Social Login and Social Comments Plugin WordPress plugin before 7.13.30 does not sanitise and escape the urls parameter in its the_champ_sharing_count AJAX action (available to both unauthenticated and authenticated users) before outputting it back in…
[*, 7.13.30)
7.13.30
15/03/2022
Social Share, Social Login and Social Comments <= 7.10.6 – Authentication Bypass
The Social Share, Social Login and Social Comments plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the 'the_champ_user_auth' AJAX action in versions up to, and including, 7.10.6. This makes it possible…
*-7.10.6
7.11
03/03/2018
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.