CVE · Medium

CVE-2024-31307 — Easy Social Share Buttons [easy-social-share-buttons3] < 9.5

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-31307 Easy Social Share Buttons [easy-social-share-buttons3] < 9.5 Missing Authorization Medium 6.3 < 9.5 9.5 2024-04-05

CVE-2024-31307

The Easy Social Share Buttons plugin for WordPress contains a broken access control flaw that was discovered by Rafie Muhammad and reported through Patchstack. The vulnerability stems from missing authorization, authentication, or nonce verification in a plugin function, allowing unprivileged users to perform actions normally restricted to higher-privilege accounts. This security issue affects versions prior to 9.5, where it has been remedied.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.