Impact
The plugin contains a CSRF flaw that permits an attacker to submit forged requests to the WordPress site. A logged‑in user who visits a malicious page could have actions performed on their behalf, such as altering settings or posting content. This weakness is identified as CWE‑352 and can compromise the integrity of the site and expose sensitive data if abused.
Affected Systems
Affected systems include the Analytify Simple Social Media Share Buttons plugin for WordPress. All released versions up to and including 6.2.0 are impacted. Version 6.2.1 and later incorporate the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity. No EPSS data is available, and the flaw is not listed in the CISA KEV catalog. Exploitation likely requires the victim to be authenticated and visit a crafted page that triggers the CSRF request, making the risk significant for sites using this plugin.
OpenCVE Enrichment