Social-Share-Buttons SQL Injection Vulnerability

Vulnerability

A critical SQL injection vulnerability has been identified in the Social Share Buttons WordPress plugin, specifically in version 2.2.3. The vulnerability resides in the 'project_id' parameter, allowing attackers to manipulate database queries. Exploitation of this vulnerability could lead to unauthorized access to and theft of the entire database contents.

Impact

Exploitation of this vulnerability allows for complete database access, enabling attackers to retrieve and potentially misuse all stored data.

Reproduction

The vulnerability can be reproduced by sending a POST request to the WordPress site with the Social Share Buttons plugin active. The request must include a crafted 'project_id' parameter that contains malicious SQL payloads. This can be done using a tool like Burp Suite or through a custom script that automates the process.

Added: Jan 13, 2026, 11:44 PM
Updated: Jan 13, 2026, 11:44 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
9.7
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.