#VU17475 Privilege escalation in Simple Social Buttons
Published: February 12, 2019 / Updated: February 12, 2019
Vulnerability identifier: #VU17475
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear
CVE-ID: N/A
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerable software:
Simple Social Buttons
Simple Social Buttons
Software vendor:
WPBrigade
WPBrigade
Description
The vulnerability allows a remote attacker to gain elevated privileges.
The weakness exists due to improper application design flow, chained with lack of permission check. A remote attacker can gain elevated privileges and perform unauthorized actions in WordPress to modify WordPress installation options from the
The weakness exists due to improper application design flow, chained with lack of permission check. A remote attacker can gain elevated privileges and perform unauthorized actions in WordPress to modify WordPress installation options from the
wp_options table that may allows to take over sites by installing backdoors or taking over admin accounts.Remediation
Update to version 2.0.22.