Description
WordPress Plugin AddToAny Share Buttons is prone to a host header injection vulnerability because it fails to properly validate an HTTP request header. A successful attack may allow attackers to insert a crafted host header to navigate the victim to the attacker's domain. WordPress Plugin AddToAny Share Buttons version 1.7.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.15 or latest
References
Related Vulnerabilities
WordPress Plugin Event Registration 'id' Parameter SQL Injection (5.43)
WordPress Plugin Ultimate Membership Pro SQL Injection (6.4)
MySQL CVE-2016-9843 Vulnerability (CVE-2016-9843)
WordPress Plugin BP Group Documents Security Bypass (1.10)
phpBB URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2015-3880)