CVE · High

CVE-2023-5602 — Social Media Share Buttons & Social Sharing Icons [ultimate-social-media-icons] < 2.8.6

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-5602 Social Media Share Buttons & Social Sharing Icons [ultimate-social-media-icons] < 2.8.6 Cross-Site Request Forgery (CSRF) High 8.8 < 2.8.6 2.8.6 2023-10-16

CVE-2023-5602

The Ultimate Social Media Icons plugin for WordPress before version 2.8.6 contains a Cross-Site Request Forgery vulnerability that affects multiple AJAX functions lacking proper nonce verification. An attacker could exploit this flaw by crafting a malicious request and deceiving a site administrator into clicking a link, allowing the attacker to perform unauthorized actions. This vulnerability impacts all versions through 2.8.5 and affects unauthenticated users.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.