CVE-2014-4717

WordPress Simple Share Buttons Adder <4.5 - CSRF

Title source: llm
STIX 2.1

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the Simple Share Buttons Adder plugin before 4.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) ssba_share_text parameter in a save action to wp-admin/options-general.php, which is not properly handled in the homepage, and unspecified vectors related to (2) Pages, (3) Posts, (4) Category/Archive pages or (5) post Excerpts.

Exploits (1)

exploitdb WORKING POC
by dxw · textwebappsphp
https://www.exploit-db.com/exploits/33896

Scores

EPSS 0.0027
EPSS Percentile 50.9%

Details

CWE
CWE-352
Status published
Products (35)
sharethis/simple_share_buttons_adder 1.0
sharethis/simple_share_buttons_adder 1.1
sharethis/simple_share_buttons_adder 1.2
sharethis/simple_share_buttons_adder 1.3
sharethis/simple_share_buttons_adder 1.4
sharethis/simple_share_buttons_adder 1.5
sharethis/simple_share_buttons_adder 1.6
sharethis/simple_share_buttons_adder 1.7
sharethis/simple_share_buttons_adder 1.8
sharethis/simple_share_buttons_adder 1.9
... and 25 more
Published Jul 03, 2014
Tracked Since Feb 18, 2026