Executive brief
The Google Plus One Bottom plugin for WordPress, which adds social sharing buttons to websites, contains a security flaw that allows unauthorized changes to its settings. By tricking a site administrator into clicking a malicious link, an attacker can remotely modify plugin configurations such as language settings and callback URLs. This could lead to unauthorized changes in how the website interacts with external services or how social sharing features are displayed to visitors.
Technical details
The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing or incorrect nonce validation on the googlePlusOneAdmin function. This vulnerability affects all versions up to and including 0.0.2. An unauthenticated attacker can exploit this by tricking a site administrator into performing an action, such as clicking a link, while authenticated to the WordPress dashboard. Successful exploitation allows the attacker to modify the plugin's settings in the database, specifically the plusone-lang, plusone-callback, and plusone-url options. This is a network-based attack that requires user interaction from an administrative user.
Affected products
- Google Plus One Bottom Google Plus One Bottom up to, and including, 0.0.2
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory
References
- https://plugins.trac.wordpress.org/browser/google-plus-one-bottom/tags/0.0.2/googlePlusOne.php
- https://plugins.trac.wordpress.org/browser/google-plus-one-bottom/tags/0.0.2/googlePlusOne.php
- https://plugins.trac.wordpress.org/browser/google-plus-one-bottom/tags/0.0.2/googlePlusOne.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/43af2d38-72e8-405f-a910-500fb782ded2?source=cve