Executive brief
Shareaholic is a popular WordPress plugin used for social sharing, analytics, and content discovery. A security flaw in the plugin allows users with low-level accounts (such as subscribers) to bypass intended access controls. This could allow unauthorized individuals to modify certain plugin settings or perform actions that should be restricted to site administrators, potentially disrupting site operations or configuration.
Technical details
A missing authorization (CWE-862) vulnerability exists in the Shareaholic plugin for WordPress in versions up to and including 9.7.11. The flaw stems from insufficient access control checks on certain functions, allowing an authenticated attacker with 'Subscriber' or higher privileges to execute actions that should be restricted to administrators. The attack is reachable over the network and does not require user interaction. An attacker can exploit this to modify plugin configurations or security levels. The issue is resolved in version 9.7.12.
Affected products
- Shareaholic Shareaholic up to 9.7.11
Timeline
- 2023-08-19: other: Reported by researcher Abdi Pranata
- 2024-01-31: advisory: Initial Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date