ThreatPress

WordPress Vulnerabilities Database

Back

WordPress Sharebar Plugin <= 1.2.5 - Multiple CSRF

Product
ShareBar
Description
Because of these vulnerabilities, the attackers can hijack the authentication of administrators for requests that insert cross-site scripting sequences, add or modify buttons.
Solution
Update the plugin.
Classification
Type Cross Site Request Forgery (CSRF)
OWASP Top 10 A8: Cross Site Request Forgery (CSRF)
References
CVE Mitre
CVE
Name CVE-2013-3491
Versions
Affected In <= 1.2.5
Fixed In 1.2.6
Disclosure date
2013-05-07
Credits
Charlie Eriksen via Secunia