CVE-2022-1653
Last modified
CVE-2022-1653 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
The Social Share Buttons by Supsystic WordPress plugin before 2.2.4 does not perform CSRF checks in it's ajax endpoints and admin pages, allowing an attacker to trick any logged in user to manipulate or change the plugin settings, as well as create, delete and rename projects and networks.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Supsystic | Social Share Buttons | < 2.2.4 |
References
- https://wpscan.com/vulnerability/52eff451-8ce3-4ac4-b530-3196aa82db48Exploit, Third Party Advisory
- https://wpscan.com/vulnerability/52eff451-8ce3-4ac4-b530-3196aa82db48Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1653?
How severe is CVE-2022-1653?
How do I fix CVE-2022-1653?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-1647The FormCraft WordPress plugin before 1.2.6 does not sanitis…4.8
- CVE-2022-1648Pandora FMS v7.0NG.760 and below allows a relative path trav…7.2
- CVE-2022-1649Null pointer dereference in libr/bin/format/mach0/mach0.c in…5.5
- CVE-2022-1650Improper Removal of Sensitive Information Before Storage or …9.3
- CVE-2022-1651A memory leak flaw was found in the Linux kernel in acrn_dev…7.1
- CVE-2022-1652Linux Kernel could allow a local attacker to execute arbitra…7.8
- CVE-2022-1654Jupiter Theme <= 6.10.1 and JupiterX Core Plugin <= 2.0.7 al…8.8
- CVE-2022-1655An Incorrect Permission Assignment for Critical Resource fla…6.5
- CVE-2022-1656Vulnerable versions of the JupiterX Theme (<=2.0.6) allow an…5.4
- CVE-2022-1657Vulnerable versions of the Jupiter (<= 6.10.1) and JupiterX …8.8
- CVE-2022-1658Vulnerable versions of the Jupiter Theme (<= 6.10.1) allow a…5.4
- CVE-2022-1659Vulnerable versions of the JupiterX Core (<= 2.0.6) plugin r…7.3
Are you affected by CVE-2022-1653?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
