CVE-2023-41802
The Super Socializer plugin for WordPress before version 7.13.55 contains a cross-site request forgery vulnerability affecting multiple notification-related functions that lack proper nonce validation. An unauthenticated attacker could exploit this flaw by crafting a malicious request that, if clicked by an administrator, would allow the attacker to mark notifications as read without authorization. The vulnerable functions include those handling Twitter count notifications, GDPR notifications, Facebook redirection notifications, LinkedIn redirect URL notifications, and several others.
Based on public CVE data (MITRE/NVD).