WordPress Plugin Vulnerabilities

Social Share Buttons for WordPress <= 2.7 - Unauthenticated Image Upload & Path Traversal

Description

The plugin allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded

Proof of Concept

Affects Plugins

No known fix

References

Classification

Type
TRAVERSAL
OWASP top 10
CWE

Miscellaneous

Original Researcher
Bob Matyas
Submitter
Bob Matyas
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2025-01-06 (about 1 year ago)
Added
2025-01-06 (about 1 year ago)
Last Updated
2025-01-06 (about 1 year ago)

Other