NA

CVE-2023-3320

Published: 20/06/2023 Updated: 07/11/2023
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

The WP Sticky Social plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.0.1. This is due to missing nonce validation in the ~/admin/views/admin.php file. This makes it possible for unauthenticated malicious users to modify the plugin's settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.

Vulnerable Product Search on Vulmon Subscribe to Product

wp sticky social project wp sticky social

Exploits

# Exploit Title: WP Sticky Social 101 - Cross-Site Request Forgery to Stored Cross-Site Scripting (XSS) # Dork: inurl:~/admin/views/adminphp # Date: 2023-06-20 # Exploit Author: Amirhossein Bahramizadeh # Category : Webapps # Vendor Homepage: wordpressorg/plugins/wp-sticky-social # Version: 101 (REQUIRED) # Tested on: Windows/Linux # ...
WordPress WP Sticky Social plugin version 101 suffers from cross site request forgery and cross site scripting vulnerabilities ...