Description
Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics lessbuttons allows Cross Site Request Forgery.This issue affects LessButtons Social Sharing and Statistics: from n/a through <= 1.6.1.
Published: 2025-05-07
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a Cross‑Site Request Forgery flaw that allows an attacker to change the settings of the LessButtons Social Sharing and Statistics plugin without authorization. By exploiting the missing CSRF protection, an attacker could modify configuration values such as shared URLs or feature toggles, potentially causing mis‑configured social sharing links or exposing the site to further attacks. This type of flaw undermines the integrity of the plugin’s configuration and can lead to unintended data exposure or loss of control over social features.

Affected Systems

The affected product is the WordPress LessButtons Social Sharing and Statistics plugin developed by Chris Clark. Versions from any initial release up through and including 1.6.1 are vulnerable. Any WordPress site that has installed a legacy or current version of this plugin up to 1.6.1 without applying a patch is at risk.

Risk and Exploitability

With a CVSS score of 4.3 and an EPSS of less than 1%, this weakness is considered moderate but the low exploitation probability indicates it is not widely targeted. An attacker would need to trick a logged‑in administrator into visiting a crafted URL or submitting a forged form, which is a typical CSRF attack pattern. The vulnerability is not present in CISA’s KEV catalog, so there is no evidence of widespread exploitation. Nonetheless, the potential impact on configuration integrity warrants timely remediation.

Generated by OpenCVE AI on April 30, 2026 at 13:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the LessButtons plugin to the newest version that contains the CSRF fix, or reinstall the latest release.
  • Restrict access to the plugin’s settings page to administrator accounts only, and enforce the use of WordPress nonces or a CSRF‑protection plugin to add additional layers of protection.
  • Enable comprehensive logging for plugin configuration changes and regularly audit logs to detect any unauthorized alterations.

Generated by OpenCVE AI on April 30, 2026 at 13:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-13767 Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics allows Cross Site Request Forgery. This issue affects LessButtons Social Sharing and Statistics: from n/a through 1.6.1.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics allows Cross Site Request Forgery. This issue affects LessButtons Social Sharing and Statistics: from n/a through 1.6.1. Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics lessbuttons allows Cross Site Request Forgery.This issue affects LessButtons Social Sharing and Statistics: from n/a through <= 1.6.1.
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00017}

epss

{'score': 0.0002}


Thu, 08 May 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 07 May 2025 14:45:00 +0000

Type Values Removed Values Added
Description Cross-Site Request Forgery (CSRF) vulnerability in Chris Clark LessButtons Social Sharing and Statistics allows Cross Site Request Forgery. This issue affects LessButtons Social Sharing and Statistics: from n/a through 1.6.1.
Title WordPress LessButtons Social Sharing and Statistics plugin <= 1.6.1 - Cross Site Request Forgery (CSRF) to Settings Change vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:47.280Z

Reserved: 2025-05-07T10:44:34.647Z

Link: CVE-2025-47614

cve-icon Vulnrichment

Updated: 2025-05-08T16:14:06.982Z

cve-icon NVD

Status : Deferred

Published: 2025-05-07T15:16:14.513

Modified: 2026-04-23T15:30:36.793

Link: CVE-2025-47614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T13:30:15Z

Weaknesses