Social Media Share Buttons & Social Sharing Icons < 3.0.1 - Contributor+ Stored XSS via Post Title
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.8epss 0.3%
exploitation probability
0.3%top 78% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button.
Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Affected products
Unknown · Social Media Share Buttons & Social Sharing Iconspublic PoCs found — 1
cve_referencewpscan.com/vulnerability/c2f7987b-8cac-4c02-97f7-b33bea5b5cc4/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.