Description
WordPress Plugin Simple Social Media Share Buttons-Social Sharing for Everyone is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Simple Social Media Share Buttons-Social Sharing for Everyone versions ranging from 2.0.4 and up to (and including) 2.0.21 are vulnerable.
Remediation
Update to plugin version 2.0.22 or latest
References
https://www.webarxsecurity.com/wordpress-plugin-simple-social-buttons/
https://plugins.svn.wordpress.org/simple-social-buttons/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Invite Anyone PHP Object Injection (1.3.18)
Oracle Database Server Improper Authentication Vulnerability (CVE-2012-3137)
WordPress 4.1.x PHP Object Injection (4.1 - 4.1.32)
Restlet Framework XML Injection (aka Blind XPath Injection) Vulnerability (CVE-2013-4221)
WordPress Plugin Feed Changer & Remover Cross-Site Scripting (0.2)