Update of “WordPress Sharebar plugin” (versions <= 1.4.1) arbitrary configuration to XSS stored via CSRF vulnerability

Details

Through a CSRF vulnerability discovered in the WordPressSharebar plugin (version <= 1.4.1), it is updated to XSS with arbitrary settings stored.

solution

Deactivate and remove. This plugin has been closed as of June 14, 2022 and is no longer available for download. This closure is temporary and pending full review.

Sources.

ShareBar

脆弱性情報を受け取る