CVE · Medium

CVE-2023-3977 — Social Media Share Buttons & Social Sharing Icons [ultimate-social-media-icons] < 2.8.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-3977 Social Media Share Buttons & Social Sharing Icons [ultimate-social-media-icons] < 2.8.2 Cross-Site Request Forgery (CSRF) Medium 4.3 < 2.8.2 2.8.2 2023-07-27

CVE-2023-3977

The ultimate-social-media-icons plugin prior to version 2.8.2 contains a Cross-Site Request Forgery vulnerability in its plugin installation functionality. Attackers can exploit the missing nonce verification on the handle_installation function to trick site administrators into installing arbitrary plugins from a predefined list by crafting malicious requests. An unauthenticated threat actor could leverage this flaw to install unwanted plugins if they can convince an admin to interact with a specially crafted link. This vulnerability affects multiple plugin versions from the affected developer.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.