关键漏洞信息 漏洞类型: Cross-Site Request Forgery (CSRF) CVE 编号: CVE-2025-15377 CVSS 评分: 4.3 (Medium) 公开发布日期: January 13, 2026 最后更新日期: January 14, 2026 研究者: dayea song - Ahnlab 影响的插件信息 软件类型: Plugin 插件名称: Sosh Share Buttons 插件slug: sosh-share-buttons 已修复: No 修复措施: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. 受影响版本: <= 1.1.0 描述 The Sosh Share Buttons plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing nonce validation on the 'admin_page_content' function. This makes it possible for unauthenticated attackers to update the plugin's settings via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. 参考链接 plugins.trac.wordpress.org