The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded
History

Tue, 13 May 2025 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Artlosk
Artlosk share Buttons
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:artlosk:share_buttons:*:*:*:*:*:wordpress:*:*
Vendors & Products Artlosk
Artlosk share Buttons

Mon, 03 Feb 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jan 2025 06:15:00 +0000

Type Values Removed Values Added
Description The Social Share Buttons for WordPress plugin through 2.7 allows an unauthenticated user to upload arbitrary images and change the path where they are uploaded
Title Social Share Buttons for WordPress <= 2.7 - Unauthenticated Image Upload & Path Traversal
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2025-01-27T06:00:12.163Z

Updated: 2025-02-03T14:29:29.172Z

Reserved: 2025-01-01T14:57:26.294Z

Link: CVE-2024-13117

cve-icon Vulnrichment

Updated: 2025-01-27T14:25:01.525Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-27T06:15:23.637

Modified: 2025-05-13T20:59:51.320

Link: CVE-2024-13117

cve-icon Redhat

No data.