Supsystic Social Share Buttons
cpe:2.3:a:supsystic:social_share_buttons:*:*:*:*:wordpress:*:*
- 2.2.3
A critical SQL injection vulnerability has been identified in the Social Share Buttons WordPress plugin, specifically in version 2.2.3. The vulnerability resides in the 'project_id' parameter, allowing attackers to manipulate database queries. Exploitation of this vulnerability could lead to unauthorized access to and theft of the entire database contents.
Exploitation of this vulnerability allows for complete database access, enabling attackers to retrieve and potentially misuse all stored data.
The vulnerability can be reproduced by sending a POST request to the WordPress site with the Social Share Buttons plugin active. The request must include a crafted 'project_id' parameter that contains malicious SQL payloads. This can be done using a tool like Burp Suite or through a custom script that automates the process.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.