CVE · Medium

CVE-2021-24616 — AddToAny Share Buttons [add-to-any] < 1.7.48

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2021-24616 AddToAny Share Buttons [add-to-any] < 1.7.48 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Medium 4.8 < 1.7.48 1.7.48 2021-08-10

CVE-2021-24616

The AddToAny Share Buttons plugin in versions prior to 1.7.48 fails to properly sanitize the Image URL button setting, enabling administrators and other high-privilege users to inject malicious scripts even in environments where the unfiltered_html capability has been restricted.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.