The Buffer Button <= 1.0 - Authenticated Stored Cross Site Scripting (XSS)
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
The Buffer Button WordPress plugin through 1.0 was vulnerable to Authenticated Stored Cross Site Scripting (XSS) within the Twitter username to mention text field.
Affected products
Unknown · The Buffer Button