CVE-2024-10362CVSS 4.8CMS
CVE-2024-10362: social media share buttons \& social sharing icons vulnerability
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
- CVSS
- 4.8 MEDIUM
- EPSS
- 23.81%
- Known exploited
- not in KEV
- Product
- social media share buttons \& social sharing icons
What is known
The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 2.9.1 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)