Description
WordPress Plugin AddToAny Share Buttons is prone to a host header injection vulnerability because it fails to properly validate an HTTP request header. A successful attack may allow attackers to insert a crafted host header to navigate the victim to the attacker's domain. WordPress Plugin AddToAny Share Buttons version 1.7.14 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.7.15 or latest
References
Related Vulnerabilities
WordPress Plugin iQ Block Country Cross-Site Scripting (1.2.11)
WordPress Plugin BJ Lazy Load Remote Code Execution (0.7.5)
WordPress Plugin Target First Live chat Unspecified Vulnerability (1.0)
Apache HTTP Server Resource Management Errors Vulnerability (CVE-2014-3523)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2009-4298)