CVE-2023-6878
Slick Social Share Buttons <= 2.4.11 - Authenticated (Subscriber+) Arbitrary Option Update
CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th
The Slick Social Share Buttons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'dcssb_ajax_update' function in versions up to, and including, 2.4.11. This makes it possible for authenticated attackers, with subscriber-level permissions or above to update the site options arbitrarily.
| CWE | CWE-285 |
| Vendor | remix4 |
| Product | slick social share buttons |
| Published | Jan 11, 2024 |
| Last Updated | Apr 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for remix4 slick social share buttons
Be the first to know when new high vulnerabilities affecting remix4 slick social share buttons are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
remix4 / Slick Social Share Buttons
0 ≤ 2.4.11
References
Credits
István Márton