Description
WordPress Plugin Simple Social Media Share Buttons-Social Sharing for Everyone is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin Simple Social Media Share Buttons-Social Sharing for Everyone versions ranging from 2.0.4 and up to (and including) 2.0.21 are vulnerable.
Remediation
Update to plugin version 2.0.22 or latest
References
https://www.webarxsecurity.com/wordpress-plugin-simple-social-buttons/
https://plugins.svn.wordpress.org/simple-social-buttons/trunk/readme.txt
Related Vulnerabilities
WordPress Plugin Events SQL Injection (2.3.4)
WordPress Plugin WassUp Real Time Analytics Cross-Site Scripting (1.8.3)
Internet Information Services Improper Input Validation Vulnerability (CVE-2000-0258)
WordPress Plugin WP Email Template HTML Injection (2.2.10)
WordPress Plugin FavIcon Switcher Cross-Site Request Forgery (1.2.11)