Vulnerabilities (CVE)

Filtered by vendor Warfareplugins Subscribe
Filtered by product Social Warfare
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-4842 1 Warfareplugins 1 Social Warfare 2023-11-14 N/A 5.4 MEDIUM
The Social Sharing Plugin - Social Warfare plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'social_warfare' shortcode in versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
CVE-2019-9978 1 Warfareplugins 2 Social Warfare, Social Warfare Pro 2021-07-30 4.3 MEDIUM 6.1 MEDIUM
The social-warfare plugin before 3.5.3 for WordPress has stored XSS via the wp-admin/admin-post.php?swp_debug=load_options swp_url parameter, as exploited in the wild in March 2019. This affects Social Warfare and Social Warfare Pro.