Viewing 2 replies - 1 through 2 (of 2 total)
  • Plugin Author ShareThis

    (@sharethis)

    Hey thanks for reaching out. We have attempted to address any sort of security issues in ver. 3.2.3, but Patchstack is not a very accurate source for CSRF vulnerabilities so not sure if/when they’re update their status.

    That being said, WordPress had previously reached out and did an extensive dive into our code and noted things that we have addressed in 3.2.2 and were satisfied with our approach. The plugin is not at risk for any forgery requests at this point in time so feel free to continue using it as normal.

    Remember to always keep an eye on your current user lists and do quarterly audits to remove any nefarious accounts. That will minimize your risk of users accessing your site’s DB altogether.

    Let me know if you have any more questions. Thanks!

    ShareThis

    Hector

    (@hectorsharethis)

Viewing 2 replies - 1 through 2 (of 2 total)

You must be logged in to reply to this topic.