WPIntell

Source evidence

Cross Site Request Forgery

Simple Share Buttons Adder · support · 2024-05-01T12:49:00+00:00

complaintsentiment
highseverity
0.97relevance
1replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 22 rows with source links

27.3% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

16 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
walterbe unresolved
Since a very long time I get warnings from Plesk and the recommendation to deactivate this plugin “WordPress Simple Share Buttons Adder plugin <= 8.5.0 – Cross Site Request Forgery (CSRF) Cross Site Request Forgery (CSRF) vulnerability discovered by Muhammad Daffa (Patchstack Alliance) in WordPress Plugin Simple Share Buttons Adder (versions <= 8.5.0) Date: 19.04.2023 | Source: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/simple-share-buttons-adder/simple-share-buttons-adder-846-cross-site-request-forgery “ I am using version 8.5.0 Maybe this is a faulty alert? Hello @walterbe , Thank you for reaching out with your concern regarding the “WordPress Simple Share Buttons Adder” plugin. We understand the importance of maintaining the security and integrity of your website. The alert you received from Plesk about the Cross Site Request Forgery (CSRF) vulnerability in version 8.5.0 of the Simple Share Buttons Adder plugin is legitimate. This vulnerability was indeed discovered and reported by Muhammad Daffa (Patchstack Alliance) and has been documented by Wordfence. Given the potential risk associated with this vulnerability, we strongly recommend updating the plugin to the latest version if an update is available. If no update is available or you prefer to ensure maximum security, deactivating the plugin would be the safest course of action until a patch is released. To address this issue, you can: Check for Updates : Ensure you are using the latest version of the plugin. Plugin developers often release patches to address such vulnerabilities. Consider Alternatives : If an update is not available, you might want to consider using an alternative plugin with similar functionality that is actively maintained and secure. Deactivate the Plugin : As a precaution, you can deactivate the Simple Share Buttons Adder plugin until a secure version is released. We apologize for any inconvenience this may cause and appreciate your understanding as we work to ensure the security of your website. If you have any further questions or need assistance with finding an alternative plugin, please feel free to reach out. Best regards, ShareThis Support Team

Comments

1 shown
ShareThis 2024-08-07T18:58:00+00:00

Hello @walterbe , Thank you for reaching out with your concern regarding the “WordPress Simple Share Buttons Adder” plugin. We understand the importance of maintaining the security and integrity of your website. The alert you received from Plesk about the Cross Site Request Forgery (CSRF) vulnerability in version 8.5.0 of the Simple Share Buttons Adder plugin is legitimate. This vulnerability was indeed discovered and reported by Muhammad Daffa (Patchstack Alliance) and has been documented by Wordfence. Given the potential risk associated with this vulnerability, we strongly recommend updating the plugin to the latest version if an update is available. If no update is available or you prefer to ensure maximum security, deactivating the plugin would be the safest course of action until a patch is released. To address this issue, you can: Check for Updates : Ensure you are using the latest version of the plugin. Plugin developers often release patches to address such vulnerabilities. Consider Alternatives : If an update is not available, you might want to consider using an alternative plugin with similar functionality that is actively maintained and secure. Deactivate the Plugin : As a precaution, you can deactivate the Simple Share Buttons Adder plugin until a secure version is released. We apologize for any inconvenience this may cause and appreciate your understanding as we work to ensure the security of your website. If you have any further questions or need assistance with finding an alternative plugin, please feel free to reach out. Best regards, ShareThis Support Team