Description
WordPress Plugin Sharebar is prone to an SQL injection vulnerability and a cross-site scripting vulnerability. Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Sharebar version 1.2.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.2.2 or latest
References
Related Vulnerabilities
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-4789)
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0123)
WordPress Plugin Welcart e-Commerce Multiple Vulnerabilities (1.3.12)
WordPress Improper Input Validation Vulnerability (CVE-2017-6815)
WordPress Plugin SMTP by BestWebSoft Cross-Site Scripting (1.0.9)