CVE-2024-1685
Social Media Share Buttons <= 2.1.0 - Authenticated (Subscriber+) PHP Object Injection
Record summary
CVE-2024-1685 has a selected CVSS score of 8.8 (high).
Description
The Social Media Share Buttons plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.0 via deserialization of untrusted input through the attachmentUrl parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to inject a PHP Object. No known POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code. CVE-2024-2721 is likely a duplicate to this issue.
Exploitation context
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 18, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Social Media Share ButtonsBrowse sygnoos / Social Media Share ButtonsDefault status: unaffected, unknown | CVE List | Through 2.1.0 | affected |