CyberRota Analysis
AI-GeneratedThe Social Media Share Buttons & Social Sharing Icons WordPress plugin prior to version 3.0.1 is vulnerable due to improper escaping of post titles in inline JavaScript event handlers, enabling users with Contributor roles and above to execute Stored Cross-Site Scripting (XSS) attacks. This vulnerability can be exploited when a visitor interacts with the affected buttons, particularly if a non-default icon display configuration is in use. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential security risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not escape the post title before outputting it in an inline JavaScript event handler, allowing users with the Contributor role and above to perform Stored Cross-Site Scripting attacks which are triggered when a visitor interacts with the affected button. Exploitation requires the Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 to be running a non-default icon display configuration.