S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2022-0594 Scanner

CVE-2022-0594 scanner - Improper Access Control vulnerability in Professional Social Sharing Buttons, Icons & Related Posts plugin for Wordpress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-0594
5.3
CVSS

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin before 9.7.6 does not have proper authorisation check in one of the AJAX action, available to unauthenticated (in v < 9.7.5) and author+ (in v9.7.5) users, allowing them to call it and retrieve various information such as the list of active plugins, various version like PHP, cURL, WP etc.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Professional Social Sharing Buttons, Icons & Related Posts – Shareaholic
AFFECTED< 9.7.6SAFE ✓≥ 9.7.6
Updated Aug 22, 2026View on NVD →
Detail

The Professional Social Sharing Buttons, Icons & Related Posts WordPress plugin is a tool that enables website owners to add social sharing buttons, related posts, and icons to their WordPress site effortlessly. This popular plugin provides an easy way for website visitors to share content on their social media profiles and for site admins to promote their content across various social media platforms.

However, as with any software product, there are potential vulnerabilities that hackers can exploit. CVE-2022-0594 is a vulnerability that has recently been identified in the Professional Social Sharing Buttons, Icons & Related Posts plugin before version 9.7.6. The vulnerability allows both unauthenticated users and author+ users to retrieve sensitive information about the site, such as the list of active plugins, various versions of PHP, cURL, and WP.

Unfortunately, if the CVE-2022-0594 vulnerability is exploited, it can lead to various security risks to the website owner. This includes attackers gaining access to sensitive information that could be used to launch a larger scale cyber attack. Furthermore, this vulnerability can also be used to inject malicious code or scripts into the website that will steal sensitive data from visitors.

Finally, with the pro features of s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. The platform offers a comprehensive suite of security tools and features that allows website owners to proactively identify and address potential security issues before they can be exploited. By taking advantage of these tools, busy site admins can ensure that their site remains secure and free from vulnerabilities.

 

REFERENCES

Solution Advice

Fortunately, there are several precautions that website owners can take to protect themselves from this vulnerability. These include:

  • Updating the Professional Social Sharing Buttons, Icons & Related Posts plugin to the latest version (9.7.6)
  • Enabling two-factor authentication to ensure that only authorized users can access the site
  • Limiting access to the site's backend to authorized personnel only
  • Using strong passwords and regularly changing them
  • Implementing a robust backup and recovery plan

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.