Description
WordPress Plugin AddToAny Share Buttons is prone to a host header injection vulnerability because it fails to properly validate an HTTP request header. A successful attack may allow attackers to insert a crafted host header to navigate the victim to the attacker's domain. WordPress Plugin AddToAny Share Buttons version 1.7.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.15 or latest
References
Related Vulnerabilities
OpenSSL Cryptographic Issues Vulnerability (CVE-2011-4108)
WordPress Other Vulnerability (CVE-2007-3238)
WordPress Plugin Advanced Ads-Ad Manager & AdSense Cross-Site Scripting (1.17.3)
XWiki Incorrect Authorization Vulnerability (CVE-2022-23615)
WordPress Plugin Shantz WordPress QOTD Cross-Site Request Forgery (1.2.2)