WPIntell

Source evidence

Vulnerable to Cross Site Request Forgery (CSRF)

Simple Share Buttons Adder · support · 2023-09-11T01:38:00+00:00

mixedsentiment
highseverity
0.95relevance
4replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

6 / 22 rows with source links

27.3% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

16 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
Anthony Hortin resolved
I know this has been reported in a other thread, but nothing has been done to fix it yet. Can you please look at getting this fixed please. iThemes Security is continuing to report it as an issue. Thanks. https://patchstack.com/database/vulnerability/simple-share-buttons-adder/wordpress-simple-share-buttons-adder-plugin-8-4-6-cross-site-request-forgery-csrf Hello, same alert. With a comment: “No patched version is available. No reply from the vendor.” Hello, Thank you for bringing this to our attention. This vulnerability has been solved in a previous update. We have informed our engineering team about the fact that the issue still appears on Patchstack, they have made another review of the plugin and the tests indicate that the vulnerability has already been solved. Our team is in contact with the Patchstack team so they can further review their report and update it on their website. Best, -ShareThis Support Team Thanks for the update on this. Merci 👍

Comments

4 shown
Éric Martin 2023-09-22T12:50:00+00:00

Hello, same alert. With a comment: “No patched version is available. No reply from the vendor.”

ShareThis 2023-10-19T18:32:00+00:00

Hello, Thank you for bringing this to our attention. This vulnerability has been solved in a previous update. We have informed our engineering team about the fact that the issue still appears on Patchstack, they have made another review of the plugin and the tests indicate that the vulnerability has already been solved. Our team is in contact with the Patchstack team so they can further review their report and update it on their website. Best, -ShareThis Support Team

Anthony Hortin 2023-10-20T03:05:00+00:00

Thanks for the update on this.

Éric Martin 2023-10-23T09:31:00+00:00

Merci 👍