sygnoos Vulnerabilities and Affected Products
Vulnerabilities associated with Social Media Share Buttons.
Products
Clear product- Popup Builder (WordPress plugin)2 vulnerabilities
- popup_builder2 vulnerabilities
- social_media_share_buttons2 vulnerabilities
- Social Media Share Buttons1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-1685HIGH | Social Media Share Buttons <= 2.1.0 - Authenticated (Subscriber+) PHP Object InjectionThe Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacke… CWE-502Mar 16, 2024 | CVSS8.8v3.1 | EPSS0.775% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |